env-config-f281@1.0.0
Malicious code in env-config-f281 (npm)
Analysis
The package env-config-f281@1.0.0 executes a credential-theft payload during npm install via both preinstall and postinstall scripts (node run.js). On Windows, it: (1) beacons the hostname and username to the C2 server at cpu-beaches-hay-marketplace[.]trycloudflare[.]com:443; (2) uses the fodhelper.exe UAC bypass (registry key HKCU\Software\Classes\ms-settings\Shell\Open\command) to escalate from user-integrity to SYSTEM; (3) creates a scheduled task running as NT AUTHORITY\SYSTEM that executes a PowerShell payload to dump Windows Credential Manager entries (via cmdkey /list and vaultcmd), LSA secrets from HKLM\SECURITY\Policy\Secrets, Azure CLI / MSAL authentication caches from all user profiles under C:\Users, PowerShell readline history, NuGet credential stores, and all .json/.config/.xml files under C:\ProgramData containing the strings secret, password, token, key, credential, or connectionstring; (4) exfiltrates collected credentials over HTTPS to cpu-beaches-hay-marketplace[.]trycloudflare[.]com via a GET beacon for summaries and a POST beacon for full credential dumps. On non-Windows systems, the payload simply confirms code execution to the same C2. C2 IOC: cpu-beaches-hay-marketplace[.]trycloudflare[.]com:443.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 03:41 PM
- analyzed
- Jun 18, 2026, 03:42 PM
Related advisories
- stellarfixer@1.0.0
- basic-vite@1.0.0
- approval-guardian@1.0.8
- streak-metrics-math@1.0.1
- metrics-probe-9b4c@1.0.0
- web-pool@2.3.5
- sort-btree@2.1.4
- poxios-chain@1.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.