anthropic-toolkit@0.2.0
Malicious code in anthropic-toolkit (npm)
Analysis
The package anthropic-toolkit is a combosquat targeting developers who use the @anthropic-ai/sdk package. On install, the postinstall hook (scripts/postinstall.js) collects a detailed environment fingerprint including: hostname, username, domain name, git-configured email from .gitconfig, GitHub CLI identity from ~/.config/gh/hosts.yml, email comments from SSH public key files, git remote origin URLs and reflog author emails, GCP project ID and account from ~/.config/gcloud/properties, AWS profile names from ~/.aws/config (credential lines filtered out), DNS search domain from /etc/resolv.conf, and the parent project's package.json metadata (name, author, repository). The collected data is serialized as JSON and POSTed to hxxps://npm-package-logger-228835561205[.]europe-west1[.]run[.]app over HTTPS. The package ships legitimate-looking TypeScript utility source files (retry wrapper, streaming helpers, token estimator) as cover for the postinstall recon implant.
- analyzed by
- Leitwacht
- first seen
- Jun 29, 2026, 04:57 PM
- analyzed
- Jun 29, 2026, 04:58 PM
Related advisories
- react-campaign-optimizer@1.0.0
- stream-read-35cf@1.0.0
- internallib_v557@1.0.5
- n8n-nodes-pentest-rce@1.0.1
- ts-ankle@1.1.0
- ts-einkle@1.0.9
- data-parser-utils@3.0.2
- ref-slot@1.0.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.