LWA-2026-6439 MAL-2026-6955 ↗ confirmed malware

hello244b@1.0.0

Malicious code in hello244b (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1525 · Implant Internal ImageT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The package contains only a package.json with a postinstall hook that runs inline JavaScript. On install, the hook collects environment variables matching GITHUB, ACTIONS, RUNNER, AWS, TOKEN, or SECRET patterns; fetches the GitHub Actions OIDC identity token if available; and queries the AWS EC2 instance metadata service (169[.]254[.]169[.]254) for IAM security credentials. All collected data — including env vars, OIDC token, and AWS IAM role credentials — is exfiltrated via HTTPS POST to bcd5-45-241-232-210[.]ngrok-free[.]app with path /?github_attack=1. The package has no repository, no license, and ships no functional code beyond this credential-harvesting lifecycle hook.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 07:24 PM
analyzed
Jul 7, 2026, 07:24 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.