@hibachi-xyz/ui@99.0.0
Malicious code in @hibachi-xyz/ui (npm)
T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
@hibachi-xyz/ui@99.0.0 is a dependency-confusion credential harvester. On require(), index.js iterates all environment variables filtering for patterns matching API keys, tokens, and secrets (KEY, SECRET, TOKEN, PASS, AWS, GITHUB, NPM, DOCKER, KUBE, and others). It collects the hostname, username, and output of whoami/id/cgroup, then POSTs the harvested data as JSON to jorijo[.]xyz:8443/t over HTTPS (with certificate validation disabled). The module exports an empty object, providing no legitimate functionality.
- analyzed by
- Leitwacht
- first seen
- Jul 16, 2026, 10:54 AM
- analyzed
- Jul 16, 2026, 10:54 AM
Related advisories
- @hibachi-xyz/types@99.0.0
- @hibachi-xyz/sdk@99.0.0
- @hibachi-xyz/config@99.0.0
- @hibachi-xyz/common@99.0.0
- node-as-api@2.1.6
- typescript-api-node@2.1.6
- xxdxax@1.0.1
- react-hook-scripts@5.4.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.