next-locomotive-init@1.0.0
Malicious code in next-locomotive-init (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The package next-locomotive-init@1.0.0 is a combosquat package impersonating Next.js animation utilities. On install, the postinstall.js hook collects the system username and hostname via os.userInfo().username and os.hostname(), formats them as an email address, and POSTs the data to eng0ai-sdk[.]vercel[.]app/api/telemetry. The package contains no animation functionality — its sole purpose is this host-metadata beacon.
- analyzed by
- Leitwacht
- first seen
- Jul 6, 2026, 04:08 PM
- analyzed
- Jul 6, 2026, 04:09 PM
Related advisories
- @digiptf/common@99.99.99
- pinokio-redis@1.0.127
- zredis-typed@1.0.127
- @bobfrankston/gcal@0.1.68
- @adobesign/as-dev-tools@99.9.10
- zod-pino434@1.0.127
- debugcli@4.3.4
- polymarket-trader-apis@0.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.