epic-internal-tools@99999.0.0
Malicious code in epic-internal-tools (npm)
Analysis
The package epic-internal-tools@99999.0.0 is a dependency-confusion credential stealer. Its preinstall hook collects host metadata (hostname, username, cwd, platform, architecture, Node.js version, CI environment variables) and filters process.env for credential patterns matching AWS_*, GITHUB_*, GH_*, NPM_*, EPIC_*, UE_*, HORDE_*, P4, CI, BUILD, TOKEN, KEY, and SECRET — collecting up to 30 such entries. The assembled payload is POSTed as JSON to hxxp://109[.]123[.]247[.]172/npm/epic_internal_tools. Additionally, the script performs a DNS callback to {hostname}-{username}.epic_internal_tools.npm[.]epic-dc[.]oast[.]fun, using the oast[.]fun exfiltration callback service. The package's main file (index.js) is a stub that exports an empty object — the sole purpose of the package is the preinstall credential-theft payload.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 09:06 PM
- analyzed
- Jul 2, 2026, 09:07 PM
Related advisories
- robomerge@99999.0.0
- compose-logger-stand@1.0.126
- cursed-ecto-d3ab00@1.0.0
- mjs-eslint@7.0.7
- @marketfront/actualordersnippetpopup@7.0.0
- date-fns-lite@1.0.6
- ecto-cargo-wk1tm59a@99.0.0
- cursed-modules@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.