nonenull1@1.0.0
Malicious code in nonenull1 (npm)
T1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1083 · File and Directory DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The package's main entry point (index.js) is a credential harvester. On require(), it POSTs system metadata (hostname, username, platform, Node version, git email) to crabbing-thong-overhung[.]ngrok-free[.]dev/ping, then reads files from ~/.ssh, ~/.aws, ~/.config, ~/.kube, ~/.docker, ~/.gnupg and any .env files in parent directories, collects environment variables matching token/secret/key/pass/auth patterns, and exfiltrates all of it to crabbing-thong-overhung[.]ngrok-free[.]dev/exfil via HTTPS POST.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 03:38 PM
- analyzed
- Jul 9, 2026, 03:39 PM
Related advisories
- @wagni_bot/eth-agent@1.1.1
- ts-eslint-jest@1.0.0
- jest-formatter@1.0.0
- cursed-modules@999.0.0
- ts-ankle@1.1.0
- ts-einkle@1.0.9
- react-campaign-optimizer@1.0.0
- @dilxzphrine/baileys@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.