anthropic-internal-tools@1.0.1
Malicious code in anthropic-internal-tools (npm)
Analysis
Package "anthropic-internal-tools" is a dependency-confusion attack that impersonates an internal Anthropic package name. On npm install, a preinstall hook executes index.js which: (1) reads credential files including ~/.aws/credentials, ~/.aws/config, ~/.config/gcloud/application_default_credentials.json, ~/.azure/accessTokens.json, ~/.ssh/id_rsa, ~/.npmrc, and ~/.gitconfig; (2) queries cloud metadata endpoints at hxxp://169[.]254[.]169[.]254/latest/meta-data/iam/security-credentials/ and hxxp://metadata[.]google[.]internal/computeMetadata/v1/instance/service-accounts/default/token; (3) enumerates all environment variables matching patterns for API keys, tokens, secrets, passwords, and cloud credentials; (4) collects system information (hostname, username, platform, network interfaces, /etc/hosts, /etc/resolv.conf); and (5) exfiltrates all collected data via HTTPS POST to webhook[.]site/2d1764b2-1249-4793-840f-7846d7d820cd. Both versions 1.0.1 and 1.0.2 use the same exfiltration endpoint and identical credential-theft logic; version 1.0.2 additionally reads and exfiltrates the full contents of ~/.ssh/id_rsa (the private SSH key) rather than just checking for its existence. No repository URL or verifiable provenance is provided despite a disclaimer in the source code.
- analyzed by
- Leitwacht
- first seen
- Jun 28, 2026, 05:32 AM
- analyzed
- Jun 28, 2026, 08:35 PM
Related advisories
- anthropic-internal-tools@1.0.2 same package
- anthropic-internal-tools@1.0.0 same package
- rebrandly-domains-digger@9999.0.0
- @immobiliarelabs/backstage-plugin-ldap-auth-backend@1.1.3
- executable-stories-cypress@3.1.1
- autotel-audit@0.1.15
- autotel-hono@0.4.26
- executable-stories-jest@3.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.