ebpf-tracker-action@1.0.1
Malicious code in ebpf-tracker-action (npm)
Analysis
This package executes automatically at install time through a preinstall lifecycle hook that runs its main script. On install it collects host reconnaissance — hostname, current username, home directory, configured DNS servers, the install path, and the full package manifest — and additionally reads the contents of /etc/passwd and /etc/hosts. It serializes all of this into a JSON payload and sends it via an HTTPS POST request to a hardcoded external callback domain (an OAST/Burp Collaborator endpoint). The package provides no real functionality; its sole purpose is to leak system and account information from any machine that installs it.
- analyzed by
- Leitwacht
- first seen
- Jun 17, 2026, 01:31 PM
- analyzed
- Jun 17, 2026, 01:51 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.