@dsft/ft-utils@1.5.8
Malicious code in @dsft/ft-utils (npm)
Analysis
On installation the package runs an automatic preinstall script (node index.js). The script reads the INIT_CWD environment variable to determine the directory of the project installing it, extracts that project folder name, and sends it together with the package name and a timestamp as a JSON HTTP POST to a hardcoded remote callback endpoint. Request errors are silently ignored so the beacon runs without visible output. This is dependency-confusion beacon behaviour that exfiltrates the consuming project identity to an attacker-controlled server at install time without consent.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 04:26 PM
- analyzed
- Jun 16, 2026, 04:56 PM
Related advisories
browse all confirmed advisories →Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.