LWA-2026-6616 MAL-2026-10416 ↗ confirmed malware

kuaishou@99.9.9

Malicious code in kuaishou (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Package ships only a package.json with a malicious prepare lifecycle hook. On install, the hook collects the hostname, platform, username, and full process environment variables, then POSTs them to crabbing-thong-overhung[.]ngrok-free[.]dev/?cross_os_cloud=1. If running in a GitHub Actions CI context (ACTIONS_ID_TOKEN_REQUEST_URL is set), it additionally fetches the OIDC identity token and exfiltrates it to the same endpoint, enabling cloud-credential theft via token exchange.

analyzed by
Leitwacht
first seen
Jul 11, 2026, 01:43 PM
analyzed
Jul 11, 2026, 01:43 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.