@npmresearch3/metrics-probe-dfda@1.0.0
Malicious code in @npmresearch3/metrics-probe-dfda (npm)
Analysis
The package preinstall/postinstall hooks execute run.js, which beacons the hostname and username to bug-until-lending-boulevard[.]trycloudflare[.]com:443 via HTTPS. On Windows systems: it exploits a UAC bypass (fodhelper.exe via the HKCU\Software\Classes\ms-settings\Shell\Open\command registry key) to create a scheduled task running as NT AUTHORITY\SYSTEM. The SYSTEM-level PowerShell payload extracts Windows Credential Manager entries (via cmdkey/vaultcmd), LSA secrets from HKLM\SECURITY\Policy\Secrets, Azure CLI caches and MSAL tokens from all user profiles, machine-level environment variables, PowerShell console history, NuGet/dotnet credential stores, and ProgramData config files containing password/token/secret patterns. All harvested credentials are exfiltrated to bug-until-lending-boulevard[.]trycloudflare[.]com:443 via HTTPS GET and POST requests to /beacon path. Temporary scripts are dropped as bb_*.ps1 and bb_*.txt under the system TEMP directory. On Linux systems: a simple GET beacon confirms code execution.
- analyzed by
- Leitwacht
- first seen
- Jun 21, 2026, 07:40 AM
- analyzed
- Jun 21, 2026, 07:41 AM
Related advisories
- @npmresearch3/bench-ee3e@1.0.0
- color-utils-eee0@1.0.0
- hex-conv-ae7a@1.0.0
- aikaf668897@1.0.3
- aikaf6688812@1.0.3
- yian666aikf@1.0.3
- env-config-f281@1.0.0
- buffer-wrap-67d7@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.