markdownlint-cli2-fix@99.0.6
Malicious code in markdownlint-cli2-fix (npm)
Analysis
A package named markdownlint-cli2-fix (a combosquat of the well-known markdownlint-cli2) ran a postinstall script on npm install that collected the victim's public IP, geolocation, hostname, username, OS platform/arch/kernel, process listing, network interfaces, and all environment variables. It specifically harvested credential tokens including NPM_TOKEN, GITHUB_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, OPENAI_API_KEY, ANTHROPIC_API_KEY, and STRIPE_SECRET_KEY. The full reconnaissance payload was then POSTed as JSON (3387 bytes) to the Burp Collaborator URL i0jvc03bvcjt40q39f5fx8671y72vxjm[.]oastify[.]com via HTTP. The request included the headers X-Poc-Type: dependency-confusion and X-Poc-Package: markdownlint-cli2-fix. The package also queried ip-api[.]com for geolocation data. The credential theft pattern targeting NPM_TOKEN and GITHUB_TOKEN indicates this was aimed at enabling self-propagation into downstream packages the victim maintains.
- analyzed by
- Leitwacht
- first seen
- Jun 23, 2026, 06:20 PM
- analyzed
- Jun 23, 2026, 06:21 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.