data-utils-bcf2@1.0.0
Malicious code in data-utils-bcf2 (npm)
Analysis
This package contains a single run.js executed automatically via both the preinstall and postinstall npm lifecycle hooks. On Linux it fingerprints the host/container and harvests cloud and CI/CD credentials: it requests AWS ECS task-role IAM credentials from the container credential endpoint (169[.]254[.]170[.]2), collects environment-injected AWS keys and session tokens, and grabs CI secrets such as GitHub Actions OIDC/runtime tokens and npm tokens. It enumerates SSH key files and reads ECS task metadata and container-escape indicators (mounts, capabilities, docker socket). It then uses the stolen task role to call AWS DynamoDB (list/describe tables and write an item). On Windows it performs a fodhelper-based UAC bypass through an ms-settings registry hijack, registers a SYSTEM-level scheduled task, overwrites a security-tool findings.xml with a falsified verdict, and steals workflow logs and tool configuration. All collected data is exfiltrated via HTTPS POST to a Cloudflare-tunnel command-and-control endpoint.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 03:36 AM
- analyzed
- Jun 18, 2026, 03:52 AM
Related advisories
- typescript-util-core@7.1.5
- typescript-util-core@3.5.0
- system-driver@1.0.1
- pretty-pino-logger@2.0.2
- prettier-logger@0.1.4
- pino-pretty-logger@1.1.1
- pino-formatter@1.1.12
- internallib_v557@1.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.