@thales-dis-dr/drmcl-ts-shared@99.99.99
Malicious code in @thales-dis-dr/drmcl-ts-shared (npm)
Analysis
This package contains no real functionality (index.js is an empty stub). Its sole purpose is install-time host reconnaissance and exfiltration. Both the preinstall and install lifecycle scripts collect the current username, hostname, working directory, and package name, base64-encode them, and exfiltrate the data two ways: an HTTPS GET request carrying the encoded data in the URL path to an attacker-controlled callback host, and a DNS lookup of a hostname whose labels encode the same data (DNS-based exfiltration). The package uses a private-looking scoped name and an absurdly high synthetic version number (99.99.99), the hallmark of a dependency-confusion attack designed to be resolved in place of a legitimate internal package and beacon the victim host on install.
- analyzed by
- Leitwacht
- first seen
- Jun 17, 2026, 07:57 PM
- analyzed
- Jun 17, 2026, 09:54 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.