ue-jenkins-buildkite@99999.0.0
Malicious code in ue-jenkins-buildkite (npm)
Analysis
On preinstall, this package executes a script that collects the installer's hostname, username, working directory, platform, architecture, Node.js version, npm agent, and CI environment indicators (HORDE_AGENT, GITHUB_ACTIONS, JENKINS_URL, TEAMCITY_VERSION). It then filters environment variables matching AWS_, GITHUB_, GH_, NPM_, EPIC_, UE_, HORDE_, P4, CI, BUILD, TOKEN, KEY, or SECRET (up to 30 values) and POSTs the full data bundle as JSON to hxxp://109[.]123[.]247[.]172/npm/ue_jenkins_buildkite. Additionally, it performs a DNS lookup to a hostname-username digest at the domain .ue_jenkins_buildkite.npm[.]epic-dc[.]oast[.]fun (an interact.sh-style callback service). The package exports an empty module and has no legitimate functionality.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 09:06 PM
- analyzed
- Jul 2, 2026, 09:08 PM
Related advisories
- epic-internal-tools@99999.0.0
- robomerge@99999.0.0
- compose-logger-stand@1.0.126
- cursed-ecto-d3ab00@1.0.0
- mjs-eslint@7.0.7
- @marketfront/actualordersnippetpopup@7.0.0
- date-fns-lite@1.0.6
- ecto-cargo-wk1tm59a@99.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.