ripshakti@80.0.0
Malicious code in ripshakti (npm)
Analysis
During npm install, the preinstall hook automatically executes index.js which steals cloud credentials and environment secrets from the installation host. The script queries the AWS EC2 metadata service (169[.]254[.]169[.]254) to harvest IAM security credentials (AccessKeyId, SecretAccessKey, SessionToken), the instance identity document, user-data content, and extensive instance metadata (hostname, IPs, instance-id, type, availability-zone, region, AMI-id, security groups, MAC addresses). It also targets AWS ECS/Fargate containers via 169[.]254[.]170[.]2 using the AWS_CONTAINER_CREDENTIALS_RELATIVE_URI and AWS_CONTAINER_CREDENTIALS_FULL_URI environment variables. Additionally, it filters all environment variables for patterns matching key, secret, token, password, auth, credential, api, aws, database, and other sensitive terms. All stolen data is base64-encoded and exfiltrated via HTTPS GET requests to the interaction-testing host oastify[.]com at the path 9x7dxkrzy9hpff6ds3y1umla218swik7[.]oastify[.]com/?d=[base64].
- analyzed by
- Leitwacht
- first seen
- Jun 29, 2026, 06:19 PM
- analyzed
- Jun 29, 2026, 06:20 PM
Related advisories
- anthropic-internal-tools@1.0.0
- date-format-helper2@1.0.4
- hunsterx-package@7.0.1
- delta-time-32bb@1.0.0
- hex-conv-ae7a@1.0.0
- mypocmaliciouspackage-cursorpt1@4.0.0
- simple-date-formatter-util-11@1.0.0
- simple-date-formatter-util-4@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.