LWA-2026-5584 MAL-2026-5890 ↗ confirmed malware

@dsft/ft-utils@1.5.8

Malicious code in @dsft/ft-utils (npm)

Analysis

On installation the package runs an automatic preinstall script (node index.js). The script reads the INIT_CWD environment variable to determine the directory of the project installing it, extracts that project folder name, and sends it together with the package name and a timestamp as a JSON HTTP POST to a hardcoded remote callback endpoint. Request errors are silently ignored so the beacon runs without visible output. This is dependency-confusion beacon behaviour that exfiltrates the consuming project identity to an attacker-controlled server at install time without consent.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 04:26 PM
analyzed
Jun 16, 2026, 04:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.