fmt-helpers-794b@1.0.0
Malicious code in fmt-helpers-794b (npm)
Analysis
This npm package executes a payload automatically on installation via both preinstall and postinstall hooks (node run.js). On Linux/CI it enumerates all environment variables and harvests CI/CD and cloud secrets: GitHub Actions tokens (GITHUB_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN/URL, ACTIONS_RUNTIME_TOKEN), NPM_TOKEN, environment AWS credentials, and ECS task-role IAM credentials retrieved from the container credential endpoint at 169[.]254[.]170[.]2. It also probes SSH key files, reads ECS task metadata (task ARN, cluster), performs container-escape reconnaissance (mounts, capabilities, docker socket, init process), and uses the stolen ECS task role to list, describe, and write items to a DynamoDB table. On Windows it performs a fodhelper.exe UAC bypass via an ms-settings registry hijack, registers a SYSTEM-level scheduled task to capture privileged command output and sensitive files, and overwrites a local findings.xml verdict file. All collected data is exfiltrated over HTTPS to a Cloudflare tunnel command-and-control host.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 02:12 AM
- analyzed
- Jun 18, 2026, 02:26 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.