LWA-2026-6557 MAL-2026-10062 ↗ confirmed malware

es6-codify@2.2.0

Malicious code in es6-codify (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

es6-codify@2.2.0 is a trojanized utility library that exfiltrates environment variables and system metadata on import. At module load, the code POSTs process.env (all environment variables, including any API tokens, npm tokens, cloud credentials, and secrets), process.cwd(), process.version, and command-line arguments to jhyugdawjdxlkanm.casa:443/post-d via HTTPS. The package presents itself as a collection of ES6+ string/array/object helpers with a README and standard build tooling, but the exfiltration runs silently in the background whenever the package is required or imported.

analyzed by
Leitwacht
first seen
Jul 9, 2026, 02:23 PM
analyzed
Jul 9, 2026, 02:24 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.