LWA-2026-6138 MAL-2026-6673 ↗ confirmed malware

anthropic-toolkit@0.2.0

Malicious code in anthropic-toolkit (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1087 · Account DiscoveryT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package anthropic-toolkit is a combosquat targeting developers who use the @anthropic-ai/sdk package. On install, the postinstall hook (scripts/postinstall.js) collects a detailed environment fingerprint including: hostname, username, domain name, git-configured email from .gitconfig, GitHub CLI identity from ~/.config/gh/hosts.yml, email comments from SSH public key files, git remote origin URLs and reflog author emails, GCP project ID and account from ~/.config/gcloud/properties, AWS profile names from ~/.aws/config (credential lines filtered out), DNS search domain from /etc/resolv.conf, and the parent project's package.json metadata (name, author, repository). The collected data is serialized as JSON and POSTed to hxxps://npm-package-logger-228835561205[.]europe-west1[.]run[.]app over HTTPS. The package ships legitimate-looking TypeScript utility source files (retry wrapper, streaming helpers, token estimator) as cover for the postinstall recon implant.

analyzed by
Leitwacht
first seen
Jun 29, 2026, 04:57 PM
analyzed
Jun 29, 2026, 04:58 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.