@marketfront/fingerprint@7.0.0
Malicious code in @marketfront/fingerprint (npm)
Analysis
The package @marketfront/fingerprint@7.0.0 is a trojanized package that ships no real source code — only a heavily obfuscated postinstall script (scripts/postinstall.js, 161KB) encoded with javascript-obfuscator. On install, the postinstall hook runs automatically. The obfuscated payload contains anti-debug and anti-VM checks: it scans process.argv and process.env.NODE_OPTIONS for sandbox/debugger indicators, runs a timing loop to detect breakpoints, and reconstructs its payload strings at runtime via char-code decoding. The package claims to be an internal authentication client from "Marketfront Platform Engineering" but the repository, documentation, and issue-tracker URLs (github[.]marketfront[.]io, docs[.]marketfront[.]io, jira[.]marketfront[.]io) are non-resolving. The dist/index.js is a stub that re-exports a non-existent src/index.js. This package is part of the same campaign as @marketfront/actualordersnippetpopup@7.0.0, which has been independently confirmed as malware.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 08:45 AM
- analyzed
- Jul 2, 2026, 08:52 AM
Related advisories
- @marketfront/changefilter@7.0.0
- @marketfront/actualordersnippetpopup@7.0.0
- @marketfront/basemarkettemplate@7.0.0
- @marketfront/bannerpopup@7.0.0
- hardhat-plugin-solidity@2.3.1
- lessload@1.0.1
- @digitalcnzz/embedded-sdk@1.0.7
- @immobiliarelabs/backstage-plugin-ldap-auth-backend@1.1.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.