search-from-search@999.99.99
Malicious code in search-from-search (npm)
Analysis
The package search-from-search@999.99.99 uses dependency confusion (sentinel version 999.99.99) to be installed inside CI pipelines. On npm install, both its preinstall and postinstall hooks run callback.js, which performs extensive system reconnaissance: collects hostname, OS, platform, architecture, user identity (username, uid, gid, homedir, shell), local and external IP addresses, working directory, Node.js version, and CI-environment detection. It then dumps ALL environment variables — including NPM_TOKEN, GITHUB_TOKEN, AWS credentials, and other secrets — and POSTs the entire data payload as JSON to the C2 endpoint at 132[.]243[.]20[.]244:8000/api/collect over plain HTTP.
- analyzed by
- Leitwacht
- first seen
- Jun 22, 2026, 06:10 PM
- analyzed
- Jun 22, 2026, 06:10 PM
Related advisories
- sync-external@1.6.0
- buffer-wrap-67d7@1.0.0
- wormgpt-cli@1.0.1
- streak-metrics-core@1.0.0
- @cryptosrvc/shift-sdk-v4@1.0.77
- @shiftmarkets/shift-exchange-root@3.9.9
- system-performance-helper@1.0.1
- n8n-nodes-port-scanner@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.