configration@2.3.5
Malicious code in configration (npm)
Analysis
configration@2.3.5 is a typosquat of "configuration". When required, index.js spawns a detached child process running lib/initializeCaller.js, which POSTs all environment variables (process.env) to a C2 endpoint at hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/6c1d60d35852ef0c05df, then executes arbitrary code returned by the C2 server via new Function("require", response.data). The payload retries up to 5 times and suppresses console output during the operation. This exfiltrates credentials, API keys, and tokens from the environment and enables remote code execution on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 12:22 PM
- analyzed
- Jul 7, 2026, 12:23 PM
Related advisories
- chai-smart@2.3.5
- express-mongo-limit@2.0.1
- zluri-ad-connector@9.9.9
- pinokio-redis@1.0.127
- @bobfrankston/gcal@0.1.68
- @bobfrankston/mailx-store-web@0.1.35
- debugcli@4.3.4
- polymarket-trader-apis@0.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.