LWA-2026-6231 MAL-2026-6763 ↗ confirmed malware

@marketfront/actualordersnippetpopup@7.0.0

Malicious code in @marketfront/actualordersnippetpopup (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

Package @marketfront/actualordersnippetpopup@7.0.0 is a trojanized dotenv impersonator. It ships a 160KB javascript-obfuscator-obfuscated postinstall script (scripts/postinstall.js) with anti-debug/tamper detection, hex-escaped strings, and atob usage — wildly disproportionate to its declared telemetry purpose. The package has no actual source code (dist/index.js references a non-existent src/index.js), zero dependencies despite claiming to be a dotenv wrapper, and uses a fabricated company identity (marketfront[.]io — a custom domain, not a real company). The obfuscated postinstall likely exfiltrates environment variables from the installer's system.

analyzed by
Leitwacht
first seen
Jul 2, 2026, 08:36 AM
analyzed
Jul 2, 2026, 08:43 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.