monitoring-service-util@1.0.0
Malicious code in monitoring-service-util (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1105 · Ingress Tool Transfer
Analysis
On install, monitoring-service-util@1.0.0 executes a base64-encoded payload that steals the NPM_TOKEN environment variable, archives the victim's /root/.codex directory, and publishes the stolen codebase as node-fsagent@5.0.<timestamp> to the npm registry using the stolen token. The payload writes a .npmrc file with the stolen token for authentication and logs its activity to /tmp/.sysmon.log. This is a self-propagating worm that uses the victim's own npm credentials to exfiltrate their codebase and re-publish it under the attacker's package name.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 09:31 PM
- analyzed
- Jul 13, 2026, 09:32 PM
Related advisories
- font-huge@2.5.3
- auth-gen-next@1.7.13
- font-hub@1.5.2
- svg-fetcher@2.4.1
- cookie-sign@2.3.5
- babel-preset-lib-client@4.9.11
- kuaishou@99.9.9
- chai-as-doc@2.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.