@marketfront/baobabtech@7.0.0
Malicious code in @marketfront/baobabtech (npm)
Analysis
The package @marketfront/baobabtech@7.0.0 impersonates an internal database utility but contains no actual library code — the entire package is a 163KB obfuscated JavaScript postinstall script. The postinstall hook runs on install and uses javascript-obfuscator with anti-debugging measures that scan for profiler and debugger tools. The package's dist/index.js is a stub that requires a non-existent file, confirming the package has no real functionality beyond the obfuscated install-time payload. The publisher email (a free encrypted email service) does not match the claimed company domain, consistent with a throwaway account pattern.
- analyzed by
- Leitwacht
- first seen
- Jul 1, 2026, 11:09 PM
- analyzed
- Jul 1, 2026, 11:10 PM
Related advisories
- @marketfront/fingerprint@7.0.0
- @marketfront/changefilter@7.0.0
- @marketfront/actualordersnippetpopup@7.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.