none123s@0.1.0
Malicious code in none123s (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
The package contains a postinstall hook that collects system information (hostname, platform, /etc/hostname, /etc/hosts, /etc/motd, /var/log/cloud-init-output.log, and directory listings of /opt/, /root/, the home directory, and /etc/permiso/) and exfiltrates it via HTTP POST to webhook[.]site/43a8680e-b580-40f5-b7aa-f089ac659712 with the query parameter vendor_identification=1. The package has no other code or functionality.
- analyzed by
- Leitwacht
- first seen
- Jul 8, 2026, 06:31 PM
- analyzed
- Jul 8, 2026, 06:31 PM
Related advisories
- cdc-market@99.9.9
- playerdata-core@9.9.1
- @vwfs-its/sf-sac-frontend@20.1.1
- dependency_confusions@99.9.9
- @comcastdevxplatforms/plugin-tenancyinformation@28.1.1
- @devxprotect/plugin-devxprotect-experience@22.2.1
- @devxdiscover/devhub-ui@24.1.4
- cpcz-common@22.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.