LWA-2026-5680 MAL-2026-6356 ↗ confirmed malware

safe-json-38bd@1.0.0

Malicious code in safe-json-38bd (npm)

Analysis

A package advertised as a JSON utility whose only real content is a cross-platform credential-stealing dropper. Its manifest runs the payload on both the preinstall and postinstall lifecycle hooks, so it executes automatically on install. On Linux/CI the payload enumerates all environment variable names and exfiltrates CI and cloud secrets, including AWS access keys, session tokens, GitHub and npm tokens, and GitHub Actions OIDC/runtime tokens. It requests ECS task-role IAM credentials from the container metadata endpoint (169[.]254[.]170[.]2) and ECS task metadata, checks for SSH private keys, performs container-escape reconnaissance (mount table, process capabilities, presence of the Docker socket), and reads the host process startup script. When a DynamoDB table name is present in the environment it uses the stolen task role to list and describe tables and write an item. All collected data is sent via HTTPS POST to a hardcoded Cloudflare tunnel command-and-control host. On Windows the payload performs a fodhelper.exe UAC bypass using an ms-settings registry hijack, registers a SYSTEM-level scheduled task to read and exfiltrate sibling build artifacts, and overwrites a findings file with a tampered verdict, beaconing results to the same C2.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 04:35 AM
analyzed
Jun 18, 2026, 06:52 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.