stream-read-35cf@1.0.0
Malicious code in stream-read-35cf (npm)
Analysis
The npm package stream-read-35cf@1.0.0 is a trojanized credential-theft implant. During npm install, the preinstall and postinstall lifecycle hooks execute run.js, which collects and exfiltrates CI/CD credentials and environment variables to a remote host. The payload captures GITHUB_TOKEN, NPM_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, and environment variable names for over 60 provider services (Anthropic, OpenAI, GitHub, GitLab, Slack, Stripe, Twilio, Vercel, Netlify, DigitalOcean, npm, Hugging Face, SendGrid, Cloudflare, Docker, PyPI, Cargo) from the build environment. It also queries the ECS metadata endpoint (169[.]254[.]170[.]2) to steal AWS IAM role credentials and reads SSH private keys from common paths. All collected data is POSTed as JSON over HTTPS to issue-clothing-medicine-archive[.]trycloudflare[.]com:443/beacon across three phases (preinstall, postinstall, and require). On Windows, the payload additionally executes a UAC bypass via the fodhelper registry key (HKCU\Software\Classes\ms-settings\Shell\Open\command) to run a PowerShell script as SYSTEM via a scheduled task, which exfiltrates and tampers with Microsoft Defender ATP findings and workflow logs from D:\TRANSFER.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 03:45 AM
- analyzed
- Jun 18, 2026, 10:29 AM
Related advisories
- internallib_v557@1.0.5
- n8n-nodes-pentest-rce@1.0.1
- anthropic-toolkit@0.2.0
- react-campaign-optimizer@1.0.0
- buffer-wrap-67d7@1.0.0
- textdecode@1.2.7
- simple-date-formatter-new-5@1.0.0
- simple-date-formatter-util-5@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.