hunsterx-package@7.0.1
Malicious code in hunsterx-package (npm)
Analysis
hunsterx-package@7.0.1 contains a credential-harvesting implant in its preinstall.js hook. On install, the script decodes nine base64-encoded payloads via eval() that: (1) collect hostname, username, homedir, platform, and architecture; (2) enumerate network interfaces and exfiltrate private IPs; (3) exfiltrate all environment variables (including NPM_TOKEN, GITHUB_TOKEN, and other secrets); (4) read ~/.npmrc and exfiltrate NPM publish tokens; (5) query the AWS EC2 metadata service (169[.]254[.]169[.]254) for account ID and region; (6) scan the filesystem for .config, .env, .yaml, .yml, .conf, .toml files and exfiltrate their contents; (7) exfiltrate package.json; (8) use DNS resolution lookups to exfiltrate hostname, IP, and username via subdomains; and (9) send a completion ping. The postinstall.js hook also fires a DNS beacon. All data is exfiltrated to d8rqs6ri6i9md1fcfdpgirhdcr17idqdh[.]oast[.]fun via HTTPS GET requests (paths: /info, /ip, /env, /npmrc, /aws, /configfiles, /file, /pkg, /done) and DNS subdomain queries.
- analyzed by
- Leitwacht
- first seen
- Jun 22, 2026, 04:08 PM
- analyzed
- Jun 22, 2026, 04:09 PM
Related advisories
- delta-time-32bb@1.0.0
- hex-conv-ae7a@1.0.0
- mypocmaliciouspackage-cursorpt1@4.0.0
- simple-date-formatter-util-11@1.0.0
- simple-date-formatter-util-4@1.0.0
- string-formatter-pro@1.0.0
- ripshakti@80.0.0
- anthropic-internal-tools@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.