LWA-2026-5677 MAL-2026-6090 ↗ confirmed malware

data-utils-bcf2@1.0.0

Malicious code in data-utils-bcf2 (npm)

T1098.004 · SSH Authorized Keys

Analysis

This package contains a single run.js executed automatically via both the preinstall and postinstall npm lifecycle hooks. On Linux it fingerprints the host/container and harvests cloud and CI/CD credentials: it requests AWS ECS task-role IAM credentials from the container credential endpoint (169[.]254[.]170[.]2), collects environment-injected AWS keys and session tokens, and grabs CI secrets such as GitHub Actions OIDC/runtime tokens and npm tokens. It enumerates SSH key files and reads ECS task metadata and container-escape indicators (mounts, capabilities, docker socket). It then uses the stolen task role to call AWS DynamoDB (list/describe tables and write an item). On Windows it performs a fodhelper-based UAC bypass through an ms-settings registry hijack, registers a SYSTEM-level scheduled task, overwrites a security-tool findings.xml with a falsified verdict, and steals workflow logs and tool configuration. All collected data is exfiltrated via HTTPS POST to a Cloudflare-tunnel command-and-control endpoint.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 03:36 AM
analyzed
Jun 18, 2026, 03:52 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.