LWA-2026-5645 MAL-2026-6077 ↗ confirmed malware

ebpf-tracker-action@1.0.1

Malicious code in ebpf-tracker-action (npm)

Analysis

This package executes automatically at install time through a preinstall lifecycle hook that runs its main script. On install it collects host reconnaissance — hostname, current username, home directory, configured DNS servers, the install path, and the full package manifest — and additionally reads the contents of /etc/passwd and /etc/hosts. It serializes all of this into a JSON payload and sends it via an HTTPS POST request to a hardcoded external callback domain (an OAST/Burp Collaborator endpoint). The package provides no real functionality; its sole purpose is to leak system and account information from any machine that installs it.

analyzed by
Leitwacht
first seen
Jun 17, 2026, 01:31 PM
analyzed
Jun 17, 2026, 01:51 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.