ac-raf-emitter@3.0.1
Malicious code in ac-raf-emitter (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
Package declares itself a supply chain attack vector. On npm install, the preinstall hook executes curl to POST the hostname and current timestamp to webhook[.]site/54919426-084d-4288-8f80-e36ae5c76e32 — exfiltrating system identity and install time to an external webhook endpoint. The tarball contains only a package.json with no functional code.
- analyzed by
- Leitwacht
- first seen
- Jul 15, 2026, 10:18 AM
- analyzed
- Jul 15, 2026, 10:18 AM
Related advisories
- @leviosa86com/leviosa86-test@6.0.0
- @debile/require-dir@1.9.1
- @web3-helpers/core@1.0.5
- smb-common-uikit@15.2.0
- ahooks-3.7.8@13.1.1
- cppt-common@13.1.1
- utils-style-engine@10.2.4
- bimi-maker@8.2.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.