LWA-2026-5636 MAL-2026-5983 ↗ confirmed malware

metrics-probe-dc85@1.0.0

Malicious code in metrics-probe-dc85 (npm)

Analysis

This npm package executes an embedded script (run.js) at both preinstall and postinstall, so merely installing it triggers the payload. It is a cross-platform credential and secret stealer that beacons to a hardcoded Cloudflare tunnel command-and-control host over HTTPS. On Linux/CI it harvests environment variables and CI/CD secrets (GITHUB_TOKEN, NPM_TOKEN, GitHub Actions OIDC and runtime tokens), AWS credentials from the environment, and ECS task-role IAM credentials retrieved from the container credentials endpoint (169[.]254[.]170[.]2); it stats SSH private keys and authorized_keys, gathers host/network/container fingerprints, and performs container-escape reconnaissance (mounts, capabilities, docker socket, entrypoint script). It then abuses the stolen ECS role via boto3 to enumerate DynamoDB tables and write a new item. On Windows it attempts a fodhelper UAC bypass to run a scheduled task as SYSTEM and exfiltrate the elevated identity, and overwrites a security-finding XML file to tamper with analysis verdicts. All collected data is sent to the external C2 endpoint. Despite description text claiming to be an authorized security-research probe, the behaviour is indistinguishable from live malware and runs automatically on install.

analyzed by
Leitwacht
first seen
Jun 17, 2026, 03:47 AM
analyzed
Jun 17, 2026, 07:36 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.