react-campaign-optimizer@1.0.0
Malicious code in react-campaign-optimizer (npm)
Analysis
Postinstall hook (postinstall.js) automatically on install exfiltrates the complete process environment (all secrets, API keys, tokens) and performs deep host/network reconnaissance to an external C2 at 2e3bkumw[.]requestrepo[.]com via HTTPS POST. The script collects: host fingerprint (hostname, OS, platform, CPU count, memory, network interfaces, user info); routing table, ARP cache, DNS configuration, and /etc/hosts contents; running process list, open network sockets, and open file descriptors; cloud metadata from 169[.]254[.]169[.]254 (AWS/Azure/GCP IMDS), 100[.]100[.]100[.]200 (Alibaba), 100[.]64[.]0[.]1 and 169[.]254[.]0[.]23 (Baidu) across 13 paths each including /meta-data/iam/security-credentials/; internal SSRF probing of gateway IPs (10.x, 172.x, 192.168.x) and Kubernetes API endpoints on ports 80/443/6443; TCP port scan of 19 internal services (SSH, MySQL, PostgreSQL, Redis, MongoDB, Elasticsearch, Kafka, Docker, Etcd, etc.); DNS reconnaissance of ~40 internal hostnames (*.baidu[.]com, *.internal, kubernetes.default.svc); sensitive file reads (/etc/passwd, SSH private keys, kubeconfig, Docker config, .npmrc); Kubernetes service account token extraction attempt; and container environment detection. All collected data is JSON-encoded and POSTed to hxxps://2e3bkumw[.]requestrepo[.]com/{path} in phases. C2 host: 2e3bkumw[.]requestrepo[.]com (443/TCP, HTTPS). File paths: package/postinstall.js (the implant).
- analyzed by
- Leitwacht
- first seen
- Jun 24, 2026, 08:32 AM
- analyzed
- Jun 24, 2026, 08:33 AM
Related advisories
- kisama-js@0.1.8
- streak-metrics-math@1.0.1
- shiftmarkets-sdk@2.1.0
- stream-read-35cf@1.0.0
- internallib_v557@1.0.5
- n8n-nodes-pentest-rce@1.0.1
- anthropic-toolkit@0.2.0
- search-from-search@999.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.