hex-conv-ae7a@1.0.0
Malicious code in hex-conv-ae7a (npm)
Analysis
hex-conv-ae7a@1.0.0 contains a credential-harvesting implant in its preinstall, postinstall, and main entrypoint (run.js). During npm install, the script reads all environment variables including NPM_TOKEN, GITHUB_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, CI/CD tokens, and SSH key files, then exfiltrates them via HTTPS POST to auditor-enabling-furthermore-mobiles[.]trycloudflare[.]com:443/beacon. It also probes the ECS container metadata endpoint (169[.]254[.]170[.]2) for IAM role credentials and reads /proc/1/cgroup and /proc/1/cmdline for container escape indicators. On Windows, the payload attempts a UAC bypass via fodhelper and runs a scheduled task as SYSTEM to enumerate and exfiltrate Defender scan results and package tarballs from D:\TRANSFER directories.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 04:12 AM
- analyzed
- Jun 18, 2026, 10:29 AM
Related advisories
- @npmresearch3/metrics-probe-dfda@1.0.0
- color-utils-eee0@1.0.0
- vaults-monitor-cron@999.0.0
- unreal-horde-dashboard@99999.0.0
- hyperpure@1.0.0
- zomato-server@1.0.0
- mypocmaliciouspackage-cursorpt1@4.0.0
- simple-date-formatter-util-11@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.