babel-preset-lib-client@4.9.11
Malicious code in babel-preset-lib-client (npm)
Analysis
Package named babel-preset-lib-client (a combosquat of a Babel preset name) contains a recon and exfiltration payload in index.js. On execution, it collects the host's public IP (via api[.]ipify[.]org), private IPs, hostname, username, platform, all environment variables (via printenv, base64-encoded), and a directory tree of the parent directory (base64-encoded). All collected data is POSTed as a Discord webhook embed to hxxps://d3doo[.]free[.]beeceptor[.]com. The printenv capture exfiltrates any credentials present in environment variables (NPM_TOKEN, GITHUB_TOKEN, etc.). The package has no repository, no description, and no lifecycle hook — it is a standalone recon tool.
- analyzed by
- Leitwacht
- first seen
- Jul 11, 2026, 06:08 PM
- analyzed
- Jul 11, 2026, 06:09 PM
- weekly installs
- 134
Related advisories
- kuaishou@99.9.9
- chai-as-doc@2.3.5
- polymarket-mcp-v2@2.1.6
- nonenull1@1.0.0
- @wagni_bot/meteora-sdk@1.2.0
- @wagni_bot/ethereum-wallet@1.0.0
- @wagni_bot/solana-sdk@1.0.0
- @wagni_bot/orca-sdk@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.