delta-time-32bb@1.0.0
Malicious code in delta-time-32bb (npm)
Analysis
The package runs a preinstall and postinstall hook (node run.js) that collects the full environment of the install target and sends it to a remote server. On Linux it reads all environment variables including GITHUB_TOKEN, NPM_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, SSH key paths, container metadata (/proc/1/cgroup, /proc/1/cmdline), network interfaces, Docker socket presence, and the ECS IAM credentials endpoint (169[.]254[.]170[.]2) — then POSTs the data to screw-daisy-powder-pirates[.]trycloudflare[.]com/beacon. It additionally attempts DynamoDB operations using the captured AWS task role. On Windows it locates and overwrites detection-verdict findings, then escalates to SYSTEM via fodhelper.exe and a scheduled task, exfiltrating system-context data to the same C2 host.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 03:54 AM
- analyzed
- Jun 18, 2026, 10:29 AM
Related advisories
- wormgpt-cli@1.0.1
- osinthell@1.9.5
- hex-conv-ae7a@1.0.0
- mypocmaliciouspackage-cursorpt1@4.0.0
- simple-date-formatter-util-11@1.0.0
- simple-date-formatter-util-4@1.0.0
- string-formatter-pro@1.0.0
- ripshakti@80.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.