LWA-2026-6619 MAL-2026-10214 ↗ confirmed malware

babel-preset-lib-client@4.9.11

Malicious code in babel-preset-lib-client (npm)

T1195.002 · Compromise Software Supply ChainT1082 · System Information DiscoveryT1059.007 · JavaScriptT1041 · Exfiltration Over C2 ChannelT1552.001 · Credentials In Files

Analysis

Package named babel-preset-lib-client (a combosquat of a Babel preset name) contains a recon and exfiltration payload in index.js. On execution, it collects the host's public IP (via api[.]ipify[.]org), private IPs, hostname, username, platform, all environment variables (via printenv, base64-encoded), and a directory tree of the parent directory (base64-encoded). All collected data is POSTed as a Discord webhook embed to hxxps://d3doo[.]free[.]beeceptor[.]com. The printenv capture exfiltrates any credentials present in environment variables (NPM_TOKEN, GITHUB_TOKEN, etc.). The package has no repository, no description, and no lifecycle hook — it is a standalone recon tool.

analyzed by
Leitwacht
first seen
Jul 11, 2026, 06:08 PM
analyzed
Jul 11, 2026, 06:09 PM
weekly installs
134

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.