LWA-2026-6151 MAL-2026-6701 ↗ confirmed malware

ripshakti@80.0.0

Malicious code in ripshakti (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.005 · Cloud Instance Metadata APIT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

During npm install, the preinstall hook automatically executes index.js which steals cloud credentials and environment secrets from the installation host. The script queries the AWS EC2 metadata service (169[.]254[.]169[.]254) to harvest IAM security credentials (AccessKeyId, SecretAccessKey, SessionToken), the instance identity document, user-data content, and extensive instance metadata (hostname, IPs, instance-id, type, availability-zone, region, AMI-id, security groups, MAC addresses). It also targets AWS ECS/Fargate containers via 169[.]254[.]170[.]2 using the AWS_CONTAINER_CREDENTIALS_RELATIVE_URI and AWS_CONTAINER_CREDENTIALS_FULL_URI environment variables. Additionally, it filters all environment variables for patterns matching key, secret, token, password, auth, credential, api, aws, database, and other sensitive terms. All stolen data is base64-encoded and exfiltrated via HTTPS GET requests to the interaction-testing host oastify[.]com at the path 9x7dxkrzy9hpff6ds3y1umla218swik7[.]oastify[.]com/?d=[base64].

analyzed by
Leitwacht
first seen
Jun 29, 2026, 06:19 PM
analyzed
Jun 29, 2026, 06:20 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.