onboarding-respects-modal@999.99.99
Malicious code in onboarding-respects-modal (npm)
Analysis
Package onboarding-respects-modal@999.99.99 is a dependency-confusion beacon with a high synthetic version that, when installed, exfiltrates the installer's environment variables to a remote server. Both preinstall and postinstall lifecycle hooks execute callback.js, which collects the installer's hostname, platform, architecture, OS release, username, home directory, shell, local IP, external IP (via api[.]ipify[.]org), CI environment detection, and the COMPLETE process.env (including all credentials, tokens, and secrets). The collected data is POSTed as JSON to hxxp://132[.]243[.]20[.]244:8000/api/collect.
- analyzed by
- Leitwacht
- first seen
- Jun 22, 2026, 10:15 AM
- analyzed
- Jun 22, 2026, 10:16 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.