search-from-search@999.99.99
Malicious code in search-from-search (npm)
Analysis
The package search-from-search@999.99.99 uses dependency confusion (sentinel version 999.99.99) to be installed inside CI pipelines. On npm install, both its preinstall and postinstall hooks run callback.js, which performs extensive system reconnaissance: collects hostname, OS, platform, architecture, user identity (username, uid, gid, homedir, shell), local and external IP addresses, working directory, Node.js version, and CI-environment detection. It then dumps ALL environment variables — including NPM_TOKEN, GITHUB_TOKEN, AWS credentials, and other secrets — and POSTs the entire data payload as JSON to the C2 endpoint at 132[.]243[.]20[.]244:8000/api/collect over plain HTTP.
- analyzed by
- Leitwacht
- first seen
- Jun 22, 2026, 06:10 PM
- analyzed
- Jun 22, 2026, 06:10 PM
Related advisories
- sync-external@1.6.0
- buffer-wrap-67d7@1.0.0
- css-flow-render-shim@1.0.0
- wix-ssr-thunderbolt-grid-polyfill@0.1.0
- css-reading-display-polyfill@1.0.0
- css-jptvix-polyfill@1.0.0
- runtime-health@1.0.1
- colorpicker-ui@1.2.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.