hello244b@1.0.0
Malicious code in hello244b (npm)
Analysis
The package contains only a package.json with a postinstall hook that runs inline JavaScript. On install, the hook collects environment variables matching GITHUB, ACTIONS, RUNNER, AWS, TOKEN, or SECRET patterns; fetches the GitHub Actions OIDC identity token if available; and queries the AWS EC2 instance metadata service (169[.]254[.]169[.]254) for IAM security credentials. All collected data — including env vars, OIDC token, and AWS IAM role credentials — is exfiltrated via HTTPS POST to bcd5-45-241-232-210[.]ngrok-free[.]app with path /?github_attack=1. The package has no repository, no license, and ships no functional code beyond this credential-harvesting lifecycle hook.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 07:24 PM
- analyzed
- Jul 7, 2026, 07:24 PM
Related advisories
- stream-read-35cf@1.0.0
- buffer-wrap-67d7@1.0.0
- textdecode@1.2.7
- simple-date-formatter-new-5@1.0.0
- simple-date-formatter-util-5@1.0.0
- mcp-dev-toolkit@1.5.0
- @across-toolkit/eslint-config@99.0.1
- antsrcsrctest@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.