@hibachi-xyz/common@99.0.0
Malicious code in @hibachi-xyz/common (npm)
Analysis
@hibachi-xyz/common@99.0.0 is a dependency-confusion credential harvester. On require(), it enumerates all environment variables, filtering for those matching credential-related patterns (KEY, SECRET, TOKEN, PASS, PRIV, SIGN, AWS, GITHUB, NPM, DOCKER, KUBE, CF_ and others), collects the hostname, username, and container cgroup information, then exfiltrates the data as a JSON POST to jorijo[.]xyz:8443/t over HTTPS with certificate validation disabled and errors silently suppressed. The package has no repository, no lifecycle hooks, and uses version 99.0.0 to exploit dependency-confusion against internal @hibachi/* scoped packages.
- analyzed by
- Leitwacht
- first seen
- Jul 16, 2026, 10:53 AM
- analyzed
- Jul 16, 2026, 10:53 AM
Related advisories
- @hibachi-xyz/types@99.0.0
- @hibachi-xyz/sdk@99.0.0
- @hibachi-xyz/config@99.0.0
- node-as-api@2.1.6
- typescript-api-node@2.1.6
- xxdxax@1.0.1
- react-hook-scripts@5.4.2
- @web3-helpers/core@1.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.