@ravespaceio/rave-engine@99.0.1
Malicious code in @ravespaceio/rave-engine (npm)
Analysis
Dependency-confusion stub published with an inflated version number to outrank a private package of the same scoped name and win install resolution. The package.json preinstall lifecycle script executes curl against a hardcoded remote IP on port 1337, sending an install-time beacon before the package is ever used. index.js repeats the same outbound request via child_process execSync so it also fires when the module is required. The package ships no real functionality (empty exports); its only purpose is to phone home to attacker infrastructure when installed inside a targeted environment.
- analyzed by
- Leitwacht
- first seen
- Jun 17, 2026, 10:57 AM
- analyzed
- Jun 17, 2026, 11:23 AM
Related advisories
browse all confirmed advisories →Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.