LWA-2026-6347 MAL-2026-7013 ↗ confirmed malware

next-locomotive-init@1.0.0

Malicious code in next-locomotive-init (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package next-locomotive-init@1.0.0 is a combosquat package impersonating Next.js animation utilities. On install, the postinstall.js hook collects the system username and hostname via os.userInfo().username and os.hostname(), formats them as an email address, and POSTs the data to eng0ai-sdk[.]vercel[.]app/api/telemetry. The package contains no animation functionality — its sole purpose is this host-metadata beacon.

analyzed by
Leitwacht
first seen
Jul 6, 2026, 04:08 PM
analyzed
Jul 6, 2026, 04:09 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.