antsrcsrctest@1.0.0
Malicious code in antsrcsrctest (npm)
Analysis
antsrcsrctest@1.0.0 is a trojanized date-formatting utility whose preinstall hook (node preinstall.js) executes a reconnaissance and exfiltration payload. On install, the script collects the hostname, platform, working directory, and full process environment variables; runs id, whoami, hostname, and ps aux via execSync; checks for container environments by reading /.dockerenv, /proc/1/cgroup, and /proc/self/mountinfo; queries the Alibaba Cloud instance metadata endpoint (hxxp://100[.]100[.]100[.]200/latest/meta-data/) for cloud credentials; and POSTs all collected data to hxxp://101[.]35[.]44[.]248/ and hxxp://101[.]35[.]44[.]248/env.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 03:46 AM
- analyzed
- Jul 9, 2026, 03:47 AM
Related advisories
- hello244b@1.0.0
- stream-read-35cf@1.0.0
- buffer-wrap-67d7@1.0.0
- textdecode@1.2.7
- simple-date-formatter-new-5@1.0.0
- simple-date-formatter-util-5@1.0.0
- mcp-dev-toolkit@1.5.0
- @across-toolkit/eslint-config@99.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.