color-utils-eee0@1.0.0
Malicious code in color-utils-eee0 (npm)
Analysis
The package color-utils-eee0@1.0.0 runs a credential-harvesting payload on install (preinstall + postinstall scripts). On Windows, it bypasses UAC via the fodhelper.exe registry escalation technique to obtain SYSTEM privileges, then enumerates and exfiltrates Windows Credential Manager entries (cmdkey/vaultcmd), LSA secrets from the registry, Azure CLI and MSAL credential caches for all user profiles, PowerShell console history, NuGet credential stores, and ProgramData configuration files containing secrets/passwords/tokens. All harvested data is exfiltrated to meetings-bios-pot-cameron[.]trycloudflare[.]com:443 via HTTPS GET and POST beacons using the marker string "tss-daas-creds". On Linux, it signals code execution to the same host.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 07:01 AM
- analyzed
- Jun 18, 2026, 10:32 AM
Related advisories
- hex-conv-ae7a@1.0.0
- @npmresearch3/metrics-probe-dfda@1.0.0
- buffer-wrap-67d7@1.0.0
- textdecode@1.2.7
- mailconfirmer@3.3.12
- prettier-lint-lenz@2.6.4
- mkt-ui-library@45.0.0
- @solana-js/web3@1.91.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.