delta-time-32bb@1.0.0
Malicious code in delta-time-32bb (npm)
Analysis
The package runs a preinstall and postinstall hook (node run.js) that collects the full environment of the install target and sends it to a remote server. On Linux it reads all environment variables including GITHUB_TOKEN, NPM_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, SSH key paths, container metadata (/proc/1/cgroup, /proc/1/cmdline), network interfaces, Docker socket presence, and the ECS IAM credentials endpoint (169[.]254[.]170[.]2) — then POSTs the data to screw-daisy-powder-pirates[.]trycloudflare[.]com/beacon. It additionally attempts DynamoDB operations using the captured AWS task role. On Windows it locates and overwrites detection-verdict findings, then escalates to SYSTEM via fodhelper.exe and a scheduled task, exfiltrating system-context data to the same C2 host.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 03:54 AM
- analyzed
- Jun 18, 2026, 10:29 AM
Related advisories
- css-flow-render-shim@1.0.0
- css-reading-display-polyfill@1.0.0
- css-display-reading-polyfill@1.0.0
- tailwind-form-kit@0.6.2
- cbc97b7a@1.1787999998.0
- sbman@1.0.0
- sbironman@1.0.0
- wormgpt-cli@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.