unsafe-malicious-package@1.0.0
Malicious code in unsafe-malicious-package (npm)
T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
The postinstall hook in scripts/postinstall.js reads the installer's ~/.aws/credentials file and exfiltrates its contents via HTTP POST to 139[.]59[.]87[.]78:8765/listener as a JSON payload containing the timestamp, source identifier, file path, and credential content.
- analyzed by
- Leitwacht
- first seen
- Jun 25, 2026, 05:44 PM
- analyzed
- Jun 25, 2026, 05:45 PM
Related advisories
- data-parser-utils@3.0.2
- ref-slot@1.0.9
- react-campaign-optimizer@1.0.0
- block-slot@1.0.9
- zod-pino@1.0.122
- search-from-search@999.99.99
- hunsterx-package@7.0.1
- crud-respect@999.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.