backoffice-charges-module@1.999.0
Malicious code in backoffice-charges-module (npm)
Analysis
On installation the package runs a preinstall script that automatically executes a bundled script. The script collects host reconnaissance — the package name, a randomly generated execution identifier, the Node.js version, OS platform, and CPU architecture, plus a timestamp — and sends it as a JSON POST to a hardcoded remote endpoint. The package ships no real functionality (the file named as its main entry point is absent); its only behaviour is the install-time outbound beacon. The inflated version number is consistent with a dependency-confusion attempt to override an internal package of the same name.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 08:50 PM
- analyzed
- Jun 16, 2026, 08:53 PM
Related advisories
- chai-test-mocks@1.2.0
- aillmgen@4.0.2
- chai-plugin-kit@5.8.1
- easyllmai@3.0.1
- ssr-auth-sync@1.6.16
- zgmiai-claude-code@1.0.56
- zetrix-development-utils@1.0.2
- chai-plugin-helper@1.7.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.