LWA-2026-6840 MAL-2026-10712 ↗ confirmed malware

@hibachi-xyz/common@99.0.0

Malicious code in @hibachi-xyz/common (npm)

T1195.002 · Compromise Software Supply ChainT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

@hibachi-xyz/common@99.0.0 is a dependency-confusion credential harvester. On require(), it enumerates all environment variables, filtering for those matching credential-related patterns (KEY, SECRET, TOKEN, PASS, PRIV, SIGN, AWS, GITHUB, NPM, DOCKER, KUBE, CF_ and others), collects the hostname, username, and container cgroup information, then exfiltrates the data as a JSON POST to jorijo[.]xyz:8443/t over HTTPS with certificate validation disabled and errors silently suppressed. The package has no repository, no lifecycle hooks, and uses version 99.0.0 to exploit dependency-confusion against internal @hibachi/* scoped packages.

analyzed by
Leitwacht
first seen
Jul 16, 2026, 10:53 AM
analyzed
Jul 16, 2026, 10:53 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.