es6-codify@2.2.0
Malicious code in es6-codify (npm)
Analysis
es6-codify@2.2.0 is a trojanized utility library that exfiltrates environment variables and system metadata on import. At module load, the code POSTs process.env (all environment variables, including any API tokens, npm tokens, cloud credentials, and secrets), process.cwd(), process.version, and command-line arguments to jhyugdawjdxlkanm.casa:443/post-d via HTTPS. The package presents itself as a collection of ES6+ string/array/object helpers with a README and standard build tooling, but the exfiltration runs silently in the background whenever the package is required or imported.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 02:23 PM
- analyzed
- Jul 9, 2026, 02:24 PM
Related advisories
- chai-as-smart@2.3.5
- @wagni_bot/meteora-sdk@1.2.0
- @wagni_bot/ethereum-wallet@1.0.0
- @wagni_bot/solana-sdk@1.0.0
- @wagni_bot/orca-sdk@1.0.0
- @wagni_bot/pumpfun-sdk@1.0.0
- @wagni_bot/web3-toolkit@1.0.0
- @wagni_bot/binance-sdk@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.