LWA-2026-6230 MAL-2026-6766 ↗ confirmed malware

@marketfront/baobabtech@7.0.0

Malicious code in @marketfront/baobabtech (npm)

Analysis

The package @marketfront/baobabtech@7.0.0 impersonates an internal database utility but contains no actual library code — the entire package is a 163KB obfuscated JavaScript postinstall script. The postinstall hook runs on install and uses javascript-obfuscator with anti-debugging measures that scan for profiler and debugger tools. The package's dist/index.js is a stub that requires a non-existent file, confirming the package has no real functionality beyond the obfuscated install-time payload. The publisher email (a free encrypted email service) does not match the claimed company domain, consistent with a throwaway account pattern.

analyzed by
Leitwacht
first seen
Jul 1, 2026, 11:09 PM
analyzed
Jul 1, 2026, 11:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.