buffer-wrap-67d7@1.0.0
Malicious code in buffer-wrap-67d7 (npm)
Analysis
Trojanized package published under the nonsense name 'buffer-wrap-67d7' that exfiltrates environment variables, CI/CD credentials, and cloud provider secrets during npm install. In its preinstall and postinstall hooks, the package collects NPM_TOKEN, GITHUB_TOKEN, AWS access keys, SSH key paths, host/network metadata, container escape indicators (cgroup, mounts, capabilities), and ECS task IAM credentials from the AWS container metadata endpoint (169[.]254[.]170[.]2). All data is POSTed as JSON via HTTPS to coaches-participants-pound-feeds[.]trycloudflare[.]com:443/beacon. On Linux it also writes to ~/.ssh/authorized_keys for persistence. On Windows the payload uses the Fodhelper UAC-bypass technique to escalate to SYSTEM, then creates a scheduled task that exfiltrates files from D:\TRANSFER directories and product-config data. The package claims to be an authorized bug-bounty probe, but the code steals the installer's credentials, which exceeds any legitimate security research scope.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 06:20 AM
- analyzed
- Jun 18, 2026, 10:26 AM
Related advisories
- textdecode@1.2.7
- simple-date-formatter-new-5@1.0.0
- simple-date-formatter-util-5@1.0.0
- mcp-dev-toolkit@1.5.0
- @across-toolkit/eslint-config@99.0.1
- antsrcsrctest@1.0.0
- hello244b@1.0.0
- stream-read-35cf@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.