@immobiliarelabs/backstage-plugin-gitlab-backend@4.0.2
Malicious code in @immobiliarelabs/backstage-plugin-gitlab-backend (npm)
Analysis
@immobiliarelabs/backstage-plugin-gitlab-backend@4.0.2 is a trojanized clone of the legitimate Backstage GitLab plugin. The package ships a clean plugin entry point in dist/index.cjs.js and a hidden malicious payload in package/index.js — a 5.3 MB file containing a ROT13-cipher-obfuscated eval payload. At install time, package/binding.gyp executes node index.js via the GYP <!() shell-command syntax (node-gyp rebuild), suppressing all output with >/dev/null 2>&1. The payload file and binding.gyp are excluded from the package.json "files" allowlist, confirming they were injected into the tarball after the legitimate build step.
- analyzed by
- Leitwacht
- first seen
- Jun 26, 2026, 03:20 PM
- analyzed
- Jun 26, 2026, 03:24 PM
- weekly installs
- 10,854
Related advisories
- @immobiliarelabs/backstage-plugin-gitlab-backend@3.0.3 same package
- @immobiliarelabs/backstage-plugin-ldap-auth-backend@1.1.3
- @immobiliarelabs/backstage-plugin-gitlab@2.1.2
- @immobiliarelabs/backstage-plugin-gitlab@1.0.1
- theme-color-picker@2.0.28
- shadxino@1.0.7
- textify-kit@1.0.0
- solana-token-api@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.