@digiptf/common@99.99.99
Malicious code in @digiptf/common (npm)
Analysis
@digiptf/common@99.99.99 is a dependency-confusion package with no functional code (index.js exports an empty object). Both the preinstall and install lifecycle hooks collect the installer's username, hostname, current working directory, and the package name, encode them as base64, and exfiltrate them via HTTP GET to hxxps://digiptf-common[.]callback[.]m0chan[.]co[.]uk/<base64-payload>. The hooks also perform a DNS lookup (nslookup) to a base64-encoded variant of the package name at the same domain (callback[.]m0chan[.]co[.]uk) as a secondary exfiltration channel.
- analyzed by
- Leitwacht
- first seen
- Jul 6, 2026, 11:37 AM
- analyzed
- Jul 6, 2026, 11:38 AM
Related advisories
- hunsterx-package@7.0.1
- search-from-feed@999.0.0
- @dxcl/indicators-js@99.99.99
- @dxcl/transaction-js@99.99.99
- @dxcl/account-js@99.99.99
- @dxcl/customer-js@99.99.99
- ug-env-switch-ball@7.9.9
- mw-filesystem-events-nodream_compat@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.