lab-services@99.0.0
Malicious code in lab-services (npm)
Analysis
This package is a dependency-confusion squat (published at version 99.0.0 to outrank an internal package of the same name). Its package.json declares a preinstall hook that executes a bundled script on install. The script fetches the machine public IP from an external IP-echo service, then gathers host reconnaissance (hostname, public IP, current working directory, OS platform, CPU architecture and a timestamp) and POSTs that data as a JSON message to a hardcoded Discord webhook before exiting. Installing the package silently leaks identifying environment details to an attacker-controlled endpoint.
- analyzed by
- Leitwacht
- first seen
- Jun 17, 2026, 04:13 PM
- analyzed
- Jun 17, 2026, 04:21 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.