LWA-2026-6168 MAL-2026-6674 ↗ confirmed malware

ripshakti1@81.0.0

Malicious code in ripshakti1 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Upon npm install, the preinstall script automatically executes index.js which harvests cloud credentials and environment secrets from the installation machine. The script queries the AWS EC2 metadata service (169[.]254[.]169[.]254) to steal IAM temporary credentials, the instance identity document, user-data (often containing secrets), and extensive instance metadata (hostname, IP addresses, instance-id, instance-type, availability-zone, region, AMI ID, security groups, network MACs). It also queries the ECS container credential endpoint (169[.]254[.]170[.]2) using AWS_CONTAINER_CREDENTIALS_RELATIVE_URI and AWS_CONTAINER_CREDENTIALS_FULL_URI environment variables. Additionally it scrapes all environment variables for keys matching patterns like key, secret, token, password, auth, credential, api, aws, database. All stolen data is base64-encoded and exfiltrated via HTTPS GET requests containing the data in query parameters to a2de2lw03amqkgbex432znqb72du1kp9[.]oastify[.]com.

analyzed by
Leitwacht
first seen
Jun 30, 2026, 09:30 AM
analyzed
Jun 30, 2026, 09:30 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.