cursed-modules@999.0.0
Malicious code in cursed-modules (npm)
Analysis
cursed-modules@999.0.0 employs dependency-confusion (high version 999.0.0, no repository, no real functionality) to deliver a multi-phase reconnaissance and exfiltration payload. Preinstall/install/postinstall hooks all run install.js, which reads /flag, /flag.txt, HTB/GleamCTF flags, .npmrc files, environment variables, and running processes, then HTTP PUTs the collected data to 154[.]57[.]164[.]76:30728/api/modules/ECT-839201. The require-time payload in index.js runs unconditionally, performing the same reconnaissance (flag files, .npmrc, env vars, process listing, mount table) and exfiltrating to 154[.]57[.]164[.]76:30728/api/modules/ECT-654321. A secondary recon.js module scans the full system (cron jobs, network state, verdaccio registry configs, Docker indicators, supervisor configs, npm config) and exfiltrates results, also writing them to /tmp/recon-output.json. The install-phase payload is gated to fire only on CTF-like environments (paths containing /app, /challenge, /home/user or verdaccio registry), but the require-phase payload activates on every import without restriction.
- analyzed by
- Leitwacht
- first seen
- Jun 30, 2026, 08:32 PM
- analyzed
- Jun 30, 2026, 08:33 PM
Related advisories
- ts-ankle@1.1.0
- ts-einkle@1.0.9
- react-campaign-optimizer@1.0.0
- @dilxzphrine/baileys@1.0.0
- sync-external@1.6.0
- atlasora-client@1.0.0
- kisama-js@0.1.8
- ts-bn-lint@3.1.19
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.