@marketfront/actualordersnippetpopup@7.0.0
Malicious code in @marketfront/actualordersnippetpopup (npm)
Analysis
Package @marketfront/actualordersnippetpopup@7.0.0 is a trojanized dotenv impersonator. It ships a 160KB javascript-obfuscator-obfuscated postinstall script (scripts/postinstall.js) with anti-debug/tamper detection, hex-escaped strings, and atob usage — wildly disproportionate to its declared telemetry purpose. The package has no actual source code (dist/index.js references a non-existent src/index.js), zero dependencies despite claiming to be a dotenv wrapper, and uses a fabricated company identity (marketfront[.]io — a custom domain, not a real company). The obfuscated postinstall likely exfiltrates environment variables from the installer's system.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 08:36 AM
- analyzed
- Jul 2, 2026, 08:43 AM
Related advisories
- @marketfront/fingerprint@7.0.0
- @marketfront/changefilter@7.0.0
- @marketfront/basemarkettemplate@7.0.0
- date-fns-lite@1.0.6
- ecto-cargo-wk1tm59a@99.0.0
- cursed-modules@999.0.0
- auth-next-gen@1.6.29
- ripshakti1@81.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.