@withgoogle/stitch-sdk@0.1.1
Malicious code in @withgoogle/stitch-sdk (npm)
Analysis
@withgoogle/stitch-sdk@0.1.1 is a combosquat package whose name implies Google affiliation. Its preinstall hook (runs automatically on npm install) and its CLI entry point both read sensitive local files — ~/.gitconfig, ~/.git-credentials, ~/.ssh/*.pub, ~/.npmrc, ~/.docker/config.json — and run git, gh (GitHub CLI), claude (Anthropic CLI), and npm commands to harvest email addresses. All collected email addresses are exfiltrated via HTTPS GET to stitch-production[.]org/api/v1 with TLS certificate validation disabled. The README boilerplate falsely claims the preinstall hook is benign.
- analyzed by
- Leitwacht
- first seen
- Jun 19, 2026, 01:26 PM
- analyzed
- Jun 19, 2026, 01:26 PM
- weekly installs
- 87
Related advisories
- new-ts-helper@9.0.2
- new-helper@5.8.1
- ts-big-ecro@3.8.1
- stitch-design@0.1.0
- log-taker@0.0.7
- eslint-helper-1@5.0.4
- new-solt-1@0.0.9
- new-solt@0.0.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.