LWA-2026-6227 MAL-2026-6764 ↗ confirmed malware

@marketfront/advertisingdevtool@7.0.0

Malicious code in @marketfront/advertisingdevtool (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

The package @marketfront/advertisingdevtool@7.0.0 runs a heavily obfuscated postinstall script (scripts/postinstall.js, 166KB) on installation. The script is obfuscated with javascript-obfuscator, uses anti-debug timing checks, reads process.argv and process.env, and makes dynamic require() calls with obfuscated module names. The README states the package sends telemetry to telemetry[.]marketfront[.]io on install. The package has no actual source code (dist/index.js re-exports a non-existent src/index.js), no dependencies, and the repository URL points to a fake github[.]marketfront[.]io domain. The obfuscated postinstall script is a C2 beacon that phones home to telemetry[.]marketfront[.]io.

analyzed by
Leitwacht
first seen
Jul 1, 2026, 11:09 PM
analyzed
Jul 1, 2026, 11:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.