LWA-2026-5844 MAL-2026-6277 ↗ confirmed malware

search-from-search@999.99.99

Malicious code in search-from-search (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1016 · System Network Configuration DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package search-from-search@999.99.99 uses dependency confusion (sentinel version 999.99.99) to be installed inside CI pipelines. On npm install, both its preinstall and postinstall hooks run callback.js, which performs extensive system reconnaissance: collects hostname, OS, platform, architecture, user identity (username, uid, gid, homedir, shell), local and external IP addresses, working directory, Node.js version, and CI-environment detection. It then dumps ALL environment variables — including NPM_TOKEN, GITHUB_TOKEN, AWS credentials, and other secrets — and POSTs the entire data payload as JSON to the C2 endpoint at 132[.]243[.]20[.]244:8000/api/collect over plain HTTP.

analyzed by
Leitwacht
first seen
Jun 22, 2026, 06:10 PM
analyzed
Jun 22, 2026, 06:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.