@npmresearch3/bench-ee3e@1.0.0
Malicious code in @npmresearch3/bench-ee3e (npm)
Analysis
The package runs a preinstall/postinstall hook (node run.js) that harvests credentials and exfiltrates them to a remote server. On Linux/CI environments it reads GITHUB_TOKEN, NPM_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, and AWS_SESSION_TOKEN from environment variables; fetches IAM credentials from the ECS metadata endpoint (169[.]254[.]170[.]2); checks for SSH keys under /root/.ssh and /home/runner/.ssh; probes DynamoDB tables using the task role; and sends all collected data via HTTPS POST to economics-alexandria-davis-parallel[.]trycloudflare[.]com:443. On Windows it attempts UAC bypass via the fodhelper registry key (HKCU\Software\Classes\ms-settings\Shell\Open\command) and creates a scheduled task running as SYSTEM to exfiltrate whoami output to the same C2 host. The package has no repository and no documented legitimate purpose.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 02:08 AM
- analyzed
- Jul 13, 2026, 02:09 AM
Related advisories
browse all confirmed advisories →Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.