@meziizana/frontend-logger@10.0.0
Malicious code in @meziizana/frontend-logger (npm)
T1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The package is an empty shell with no functional code — only a package.json. On install, the preinstall script runs `wget` to exfiltrate the installer's username, current working directory, and hostname to webhook[.]site/f164a383-b9e7-4379-b18c-38bf41a3c152. This is a host-reconnaissance beacon: the attacker collects system metadata to identify valuable targets for follow-on compromise.
- analyzed by
- Leitwacht
- first seen
- Jul 10, 2026, 05:50 PM
- analyzed
- Jul 10, 2026, 05:50 PM
Related advisories
- paperclip-host-utils@1.0.0
- vps-adapter-core@1.0.0
- vps-new-manager@0.1.4
- @digiptf/common@99.99.99
- @adobesign/as-dev-tools@99.9.10
- npm-rce-poc@1.0.13
- datefmt-helper@1.0.0
- @immobiliarelabs/backstage-plugin-ldap-auth-backend@1.1.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.