@marketfront/advertisingdevtool@7.0.0
Malicious code in @marketfront/advertisingdevtool (npm)
Analysis
The package @marketfront/advertisingdevtool@7.0.0 runs a heavily obfuscated postinstall script (scripts/postinstall.js, 166KB) on installation. The script is obfuscated with javascript-obfuscator, uses anti-debug timing checks, reads process.argv and process.env, and makes dynamic require() calls with obfuscated module names. The README states the package sends telemetry to telemetry[.]marketfront[.]io on install. The package has no actual source code (dist/index.js re-exports a non-existent src/index.js), no dependencies, and the repository URL points to a fake github[.]marketfront[.]io domain. The obfuscated postinstall script is a C2 beacon that phones home to telemetry[.]marketfront[.]io.
- analyzed by
- Leitwacht
- first seen
- Jul 1, 2026, 11:09 PM
- analyzed
- Jul 1, 2026, 11:10 PM
Related advisories
- @marketfront/fingerprint@7.0.0
- @marketfront/changefilter@7.0.0
- @marketfront/actualordersnippetpopup@7.0.0
- date-fns-lite@1.0.6
- consumerweb@2200.4.2
- ecto-cargo-wk1tm59a@99.0.0
- cursed-modules@999.0.0
- auth-next-gen@1.6.29
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.