@marketfront/changefilter@7.0.0
Malicious code in @marketfront/changefilter (npm)
Analysis
On install, the postinstall hook (scripts/postinstall.js) executes a 164KB javascript-obfuscator-obfuscated payload. The package poses as an internal configuration loader but is published publicly on npm. The postinstall script sends telemetry to telemetry[.]marketfront[.]io and executes obfuscated code. The package has no repository, no prior versions, and uses a fake internal infrastructure domain (github[.]marketfront[.]io). The same publisher simultaneously published @marketfront/actualordersnippetpopup@7.0.0 with an identical obfuscated postinstall payload, which has been independently confirmed as malware.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 08:43 AM
- analyzed
- Jul 2, 2026, 08:46 AM
Related advisories
- @marketfront/fingerprint@7.0.0
- @marketfront/actualordersnippetpopup@7.0.0
- @marketfront/basemarkettemplate@7.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.