ollama-helpers@0.2.1
Malicious code in ollama-helpers (npm)
Analysis
ollama-helpers is a combosquat package impersonating the legitimate Ollama LLM SDK. On install, its postinstall script collects developer identity — hostname, username, git email (from ~/.gitconfig and ~/.config/git/config), GitHub login and email (from ~/.config/gh/hosts.yml), current working directory path, CI provider environment variables, GIT_AUTHOR_EMAIL/GIT_COMMITTER_EMAIL env vars, and runtime platform info — and POSTs it to npm-package-logger-228835561205[.]europe-west1[.]run[.]app over HTTPS. The package ships a publish script that deliberately creates a fake version history to appear maintained. The source utility files (health-check, cache, connection-pool, etc.) are benign stubs; the entire malicious behaviour is in scripts/postinstall.js.
- analyzed by
- Leitwacht
- first seen
- Jun 23, 2026, 01:47 PM
- analyzed
- Jun 23, 2026, 01:48 PM
Related advisories
- aikaf668897@1.0.3
- wm-idp-sdk@1.2.0
- wac-atl-context@99.9.1
- transform-es2015-classes@6.25.1
- transform-es3-member-expression-literals@6.24.0
- toast-react-slider@1.0.0
- redirect-azlazy@1.0.0
- oit-lib-oracle-util@45.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.