rtc-integration-frontend-sdk@99.9.0
Malicious code in rtc-integration-frontend-sdk (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
On install, the postinstall hook (node index.js) executes a host-reconnaissance script. It collects the system's hostname, OS platform and architecture, username, private IP addresses, public IP (queried from api[.]ipify[.]org), current working directory, and package name, then exfiltrates all of this data to a hardcoded Discord webhook URL (discord[.]com/api/webhooks/1524917003394089029/...). The webhook URL is the C2 endpoint for data exfiltration.
- analyzed by
- Leitwacht
- first seen
- Jul 10, 2026, 02:53 PM
- analyzed
- Jul 10, 2026, 02:53 PM
Related advisories
- ohcm-culture-formatting@5.0.0
- env-fast@1.0.0
- ap3-components-ui@9.999.0
- @espn-ping/react-dmed-oauth@666.0.0
- fury_frontend-andes-ui@99.9.5
- cookie-phase@2.3.5
- polymarket-mcp-v2@2.1.6
- chunk-parser@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.