crud-respect@999.99.99
Malicious code in crud-respect (npm)
Analysis
Dependency confusion attack published as crud-respect@999.99.99 with a synthetically high version to be installed ahead of a legitimate internal package. On npm install (both preinstall and postinstall hooks), the package runs callback.js which collects system information (hostname, platform, architecture, local and external IP addresses, operating system release, username, home directory, current working directory, CI environment indicators, Node.js version) and ALL process environment variables (including NPM_TOKEN, GITHUB_TOKEN, and any other secrets in the environment), then POSTs this data as a JSON payload to hxxp://132[.]243[.]20[.]244:8000/api/collect.
- analyzed by
- Leitwacht
- first seen
- Jun 22, 2026, 10:22 AM
- analyzed
- Jun 22, 2026, 10:23 AM
Related advisories
- hyperpure-core@1.0.0
- blinkit-core@1.0.0
- zomato-logger@1.0.0
- zomato-espresso@1.0.0
- zomato-core@1.0.0
- zomato-mcp@1.0.0
- @variational/common-ui@99.0.0
- @npmresearch3/metrics-probe-dfda@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.