@digitalcnzz/embedded-sdk@1.0.7
Malicious code in @digitalcnzz/embedded-sdk (npm)
Analysis
The package @digitalcnzz/embedded-sdk@1.0.7 is a trojanized clone of the Apache Superset embedded SDK. On postinstall (node .prepare.cjs), it first evades analysis by exiting if it detects sandbox environments (checking for dummy/honey tokens, CI/CD variables, sandbox hostnames/usernames, detector env vars). After passing these evasion checks and a 15-45 second randomized delay, it collects system fingerprint data (hostname, username, platform, architecture, Node version, non-internal IP addresses, registry URL) and dumps ALL environment variables (excluding only npm_lifecycle_* variables). This captured data — including NPM_TOKEN, GITHUB_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, and any other secrets present in the environment — is POSTed as JSON to open[.]larksuite[.]com (Lark/Feishu) via a bot webhook endpoint at /open-api/bot/v2/hook/{webhook-id}. The package has no repository, no README, and the only functional file is the malicious postinstall hook.
- analyzed by
- Leitwacht
- first seen
- Jun 28, 2026, 09:02 PM
- analyzed
- Jun 28, 2026, 09:09 PM
Related advisories
- util-free-ports@3.1.2
- stringfy-utils-kit@1.0.0
- sort-btree@2.1.4
- macos-ci-utils@1.0.1
- index-ulid@3.0.2
- obfus-jsxy@3.2.0
- ecto-rust-read-f3a9c1@1.0.2
- devplatform-spa-plugin-module-loader@35.8.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.