cursed-ecto-d3ab00@1.0.0
Malicious code in cursed-ecto-d3ab00 (npm)
Analysis
All four lifecycle hooks (preinstall, install, postinstall, prepare) execute identical malicious code. On install, the package runs shell commands to read flag files from common paths (/flag*, /root/flag*, /flag.txt, /app/flag*, /srv/flag*, /home/*/flag*, /flag, /run/secrets/*) and environment variables matching "flag" or "htb". It also collects hostname, user id, and working directory. All collected data is base64-encoded and exfiltrated via HTTPS GET to forward-amber-prairie-ruled[.]trycloudflare[.]com/x?d=. Additionally, the package probes a list of internal hosts (127[.]0[.]0[.]1, localhost, app, web, frontend, console, ecto, registry, backend, nginx on ports 3000, 8080, 80, 5000, 4000) and sends a PUT request to /api/modules/ECT-839201 with a JSON manifest declaring the host "PWNED" — attempting to compromise an Ecto application registry.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 11:52 AM
- analyzed
- Jul 2, 2026, 11:53 AM
Related advisories
- react-campaign-optimizer@1.0.0
- format-helper-lib@1.0.0
- wormgpt-cli@1.0.1
- simple-date-formatter-new-8@1.0.0
- simple-date-formatter-new-6@1.0.0
- simple-date-formatter-new-5@1.0.0
- n8n-nodes-http-probe@1.0.0
- n8n-nodes-probe@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.