color-utils-eee0@1.0.0
Malicious code in color-utils-eee0 (npm)
Analysis
The package color-utils-eee0@1.0.0 runs a credential-harvesting payload on install (preinstall + postinstall scripts). On Windows, it bypasses UAC via the fodhelper.exe registry escalation technique to obtain SYSTEM privileges, then enumerates and exfiltrates Windows Credential Manager entries (cmdkey/vaultcmd), LSA secrets from the registry, Azure CLI and MSAL credential caches for all user profiles, PowerShell console history, NuGet credential stores, and ProgramData configuration files containing secrets/passwords/tokens. All harvested data is exfiltrated to meetings-bios-pot-cameron[.]trycloudflare[.]com:443 via HTTPS GET and POST beacons using the marker string "tss-daas-creds". On Linux, it signals code execution to the same host.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 07:01 AM
- analyzed
- Jun 18, 2026, 10:32 AM
Related advisories
- hex-conv-ae7a@1.0.0
- @npmresearch3/metrics-probe-dfda@1.0.0
- delta-time-32bb@1.0.0
- buffer-wrap-67d7@1.0.0
- nat-ulid@3.0.2
- check-ulid@3.0.2
- vitest-pro@7.0.4
- seed-to-private@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.