LWA-2026-6234 MAL-2026-6779 ↗ confirmed malware

@marketfront/fingerprint@7.0.0

Malicious code in @marketfront/fingerprint (npm)

T1027 · Obfuscated Files or Information

Analysis

The package @marketfront/fingerprint@7.0.0 is a trojanized package that ships no real source code — only a heavily obfuscated postinstall script (scripts/postinstall.js, 161KB) encoded with javascript-obfuscator. On install, the postinstall hook runs automatically. The obfuscated payload contains anti-debug and anti-VM checks: it scans process.argv and process.env.NODE_OPTIONS for sandbox/debugger indicators, runs a timing loop to detect breakpoints, and reconstructs its payload strings at runtime via char-code decoding. The package claims to be an internal authentication client from "Marketfront Platform Engineering" but the repository, documentation, and issue-tracker URLs (github[.]marketfront[.]io, docs[.]marketfront[.]io, jira[.]marketfront[.]io) are non-resolving. The dist/index.js is a stub that re-exports a non-existent src/index.js. This package is part of the same campaign as @marketfront/actualordersnippetpopup@7.0.0, which has been independently confirmed as malware.

analyzed by
Leitwacht
first seen
Jul 2, 2026, 08:45 AM
analyzed
Jul 2, 2026, 08:52 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.