estore-client@5.0.0
Malicious code in estore-client (npm)
Analysis
estore-client@5.0.0 is a malicious package containing only a package.json with no actual source code. The preinstall, test, and preupdate lifecycle hooks all execute `wget` to exfiltrate system information (current username, working directory path, and hostname) to webhook[.]site/d32804ac-1bbb-4100-ab60-95231dd3251c/ via query parameters. The package also declares a dependency on seaport-core-16, a known malicious package. The package has no repository URL, no description, and ships no functional code.
- analyzed by
- Leitwacht
- first seen
- Jul 15, 2026, 12:48 AM
- analyzed
- Jul 15, 2026, 12:48 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.