LWA-2026-6275 MAL-2026-6737 ↗ confirmed malware

epic-internal-tools@99999.0.0

Malicious code in epic-internal-tools (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web ProtocolsT1102 · Web Service

Analysis

The package epic-internal-tools@99999.0.0 is a dependency-confusion credential stealer. Its preinstall hook collects host metadata (hostname, username, cwd, platform, architecture, Node.js version, CI environment variables) and filters process.env for credential patterns matching AWS_*, GITHUB_*, GH_*, NPM_*, EPIC_*, UE_*, HORDE_*, P4, CI, BUILD, TOKEN, KEY, and SECRET — collecting up to 30 such entries. The assembled payload is POSTed as JSON to hxxp://109[.]123[.]247[.]172/npm/epic_internal_tools. Additionally, the script performs a DNS callback to {hostname}-{username}.epic_internal_tools.npm[.]epic-dc[.]oast[.]fun, using the oast[.]fun exfiltration callback service. The package's main file (index.js) is a stub that exports an empty object — the sole purpose of the package is the preinstall credential-theft payload.

analyzed by
Leitwacht
first seen
Jul 2, 2026, 09:06 PM
analyzed
Jul 2, 2026, 09:07 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.