@marketfront/basemarkettemplate@7.0.0
Malicious code in @marketfront/basemarkettemplate (npm)
Analysis
The package @marketfront/basemarkettemplate@7.0.0 is a trojanized hollow package. It ships no functional code — dist/index.js re-exports a non-existent file. The only payload is a 166KB heavily obfuscated postinstall script (scripts/postinstall.js) that uses javascript-obfuscator with anti-debugging, anti-tampering, and environment-detection checks. On install, the postinstall reads the NODE_OPTIONS environment variable, inspects process.argv, and loads additional modules via decoded require() calls. The README fabricates a fake company and claims to send "anonymous telemetry" to telemetry[.]marketfront[.]io as a cover story for C2 beaconing. No repository, no verifiable publisher identity.
- analyzed by
- Leitwacht
- first seen
- Jul 1, 2026, 11:09 PM
- analyzed
- Jul 1, 2026, 11:13 PM
Related advisories
- @marketfront/fingerprint@7.0.0
- @marketfront/changefilter@7.0.0
- @marketfront/actualordersnippetpopup@7.0.0
- @marketfront/bannerpopup@7.0.0
- hardhat-plugin-solidity@2.3.1
- lessload@1.0.1
- @digitalcnzz/embedded-sdk@1.0.7
- @immobiliarelabs/backstage-plugin-ldap-auth-backend@1.1.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.