ecto-cargo-wk1tm59a@99.0.0
Malicious code in ecto-cargo-wk1tm59a (npm)
Analysis
Package ecto-cargo-wk1tm59a@99.0.0 runs a flag-stealing payload (steal.js) on both preinstall and postinstall hooks. The script reads flag files from common locations (/flag, /flag.txt, /root/flag.txt, /root/flag, /app/flag.txt, /app/flag, /tmp/flag.txt, /home/flag.txt), runs discovery commands (hostname, id, find / -iname "flag*", env | grep flag/htb), and exfiltrates the captured data via HTTP GET to webhook[.]site/9f1b89bd-a22f-4221-b28e-bc956b5ec8e0 with hostname and base64-encoded flag data in query parameters. It also PUTs a JSON-encoded exfil manifest to hardcoded internal service endpoints and to IP 154[.]57[.]164[.]66:30962 at path /api/modules/ECT-987654.
- analyzed by
- Leitwacht
- first seen
- Jun 30, 2026, 11:05 PM
- analyzed
- Jun 30, 2026, 11:06 PM
Related advisories
- cursed-modules@999.0.0
- auth-next-gen@1.6.29
- ripshakti1@81.0.0
- ripshakti@80.0.0
- ts-linting-builder@2.1.2
- ts-lint-builders-v2.1@2.1.0
- @digitalcnzz/embedded-sdk@1.0.7
- anthropic-internal-tools@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.