livekit-agents@0.3.4
Malicious code in livekit-agents (npm)
Analysis
The install hook (postinstall: node dist/postinstall.js) collects system information — package name and version, Node.js version, OS platform and architecture, the installer's username, hostname, and current working directory — and sends it via HTTPS POST to livekit-agents[.]xyz:443/api/metrics. The beacon silently suppresses errors and timeouts to avoid detection. The package also declares a self-dependency (livekit-agents@^0.3.1), a known bootstrapping technique.
- analyzed by
- Leitwacht
- first seen
- Jun 29, 2026, 05:37 AM
- analyzed
- Jun 29, 2026, 07:46 AM
Related advisories
- livekit-agents@0.3.0 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.