ripshakti1@81.0.0
Malicious code in ripshakti1 (npm)
Analysis
Upon npm install, the preinstall script automatically executes index.js which harvests cloud credentials and environment secrets from the installation machine. The script queries the AWS EC2 metadata service (169[.]254[.]169[.]254) to steal IAM temporary credentials, the instance identity document, user-data (often containing secrets), and extensive instance metadata (hostname, IP addresses, instance-id, instance-type, availability-zone, region, AMI ID, security groups, network MACs). It also queries the ECS container credential endpoint (169[.]254[.]170[.]2) using AWS_CONTAINER_CREDENTIALS_RELATIVE_URI and AWS_CONTAINER_CREDENTIALS_FULL_URI environment variables. Additionally it scrapes all environment variables for keys matching patterns like key, secret, token, password, auth, credential, api, aws, database. All stolen data is base64-encoded and exfiltrated via HTTPS GET requests containing the data in query parameters to a2de2lw03amqkgbex432znqb72du1kp9[.]oastify[.]com.
- analyzed by
- Leitwacht
- first seen
- Jun 30, 2026, 09:30 AM
- analyzed
- Jun 30, 2026, 09:30 AM
Related advisories
- anthropic-internal-tools@1.0.0
- @epsteinlovekids483/crossmint-wallets-sdk-pentest@1.0.0-pentest
- react-campaign-optimizer@1.0.0
- @npmresearch3/metrics-probe-dfda@1.0.0
- atlasora-utils@1.0.0
- atlasora-types@1.0.0
- atlasora-sdk@1.0.0
- atlasora-config@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.