metrics-probe-9b4c@1.0.0
Malicious code in metrics-probe-9b4c (npm)
Analysis
metrics-probe-9b4c@1.0.0 runs a credential-harvesting payload in its preinstall and postinstall hooks (node run.js). On Windows, the payload: 1. Escalates to SYSTEM via a UAC bypass (fodhelper.exe with registry manipulation) 2. Runs a SYSTEM-level PowerShell script that collects: Windows Credential Manager entries (via cmdkey and vaultcmd), LSA secrets from HKLM\SECURITY\Policy\Secrets, SYSTEM environment variables, Azure CLI/MSAL authentication caches from all user profiles, PowerShell history, NuGet/dotnet credential stores, and ProgramData config files containing secrets/tokens/passwords 3. Exfiltrates all collected credentials via HTTPS GET and POST requests to detector-blonde-instructional-circular[.]trycloudflare[.]com:443 at the /beacon endpoint with tss-daas-creds| markers 4. Cleans up the scheduled task and temporary files after execution On non-Windows systems, the payload silently confirms code execution via a beacon to the same host. C2: detector-blonde-instructional-circular[.]trycloudflare[.]com:443, path /beacon?d=tss-daas-creds|...
- analyzed by
- Leitwacht
- first seen
- Jun 21, 2026, 01:43 AM
- analyzed
- Jun 21, 2026, 01:44 AM
Related advisories
- time-format-kit@1.0.2
- env-config-f281@1.0.0
- approval-guardian@1.0.8
- streak-metrics-math@1.0.1
- color-utils-eee0@1.0.0
- delta-time-32bb@1.0.0
- hex-conv-ae7a@1.0.0
- buffer-wrap-67d7@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.