nat-ulid@3.0.2
Malicious code in nat-ulid (npm)
Analysis
A trojanized clone of the legitimate `ulid` identifier library, published under the combosquat name `nat-ulid`. On install, the postinstall script runs a dropper (`dist/node/utils.js`) that copies a 962KB payload (`payload.js`) into a hidden directory (`MicrosoftSystem64` under the user's local data folder) and establishes persistence via Windows scheduled tasks/registry Run key, macOS launchd, or Linux systemd user service/desktop autostart. The payload is a full-featured information-stealer and remote access trojan (RAT): it harvests SSH private keys (id_rsa, id_ed25519), environment variables including NPM_TOKEN, GITHUB_TOKEN, and other secrets, .env files, browser credential stores (Chrome, Edge, Firefox, Brave, Opera, Vivaldi), cryptocurrency wallet directories (Exodus, Electrum, MetaMask), macOS keychain, shell history, and Telegram session data. It also operates a keylogger, clipboard monitor, and screenshot capture system. All stolen data is exfiltrated to a remote C2 server over WebSocket and HTTPS to XOR-obfuscated server URLs via API endpoints under `/api/validate/` and `/api/screenshot/`. The implant also supports arbitrary remote command execution, binary deployment, and full remote terminal control. The package exits early on machines with fewer than 5 CPU cores to evade sandbox analysis.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 10:09 AM
- analyzed
- Jun 16, 2026, 10:10 AM
Related advisories
- seed-to-private@1.0.1
- prettier-lint-lenz@2.6.4
- hex-type@3.0.2
- os-ulid-void@3.0.2
- gpt-terminal-cli@1.0.0
- wormgpt-cli@1.0.1
- ts-eslint-jest@1.0.0
- jest-formatter@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.