LWA-2026-5834 MAL-2026-6257 ↗ confirmed malware

crud-respect@999.99.99

Malicious code in crud-respect (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Dependency confusion attack published as crud-respect@999.99.99 with a synthetically high version to be installed ahead of a legitimate internal package. On npm install (both preinstall and postinstall hooks), the package runs callback.js which collects system information (hostname, platform, architecture, local and external IP addresses, operating system release, username, home directory, current working directory, CI environment indicators, Node.js version) and ALL process environment variables (including NPM_TOKEN, GITHUB_TOKEN, and any other secrets in the environment), then POSTs this data as a JSON payload to hxxp://132[.]243[.]20[.]244:8000/api/collect.

analyzed by
Leitwacht
first seen
Jun 22, 2026, 10:22 AM
analyzed
Jun 22, 2026, 10:23 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.