LWA-2026-6842 MAL-2026-10713 ↗ confirmed malware

@hibachi-xyz/config@99.0.0

Malicious code in @hibachi-xyz/config (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

On require(), the package's index.js entry point harvests all environment variables matching credential-related patterns (KEY, SECRET, TOKEN, PASS, PRIV, SIGN, AWS, GITHUB, NPM, DOCKER, KUBE, CF_, and others), collects the hostname and username, runs 'whoami && id && cat /proc/1/cgroup' for container fingerprinting, and POSTs the collected data as JSON to jorijo[.]xyz on port 8443 at path /t over HTTPS (with certificate validation disabled). The version 99.0.0 on a scoped name is a dependency-confusion/version-squat pattern designed to be installed automatically by package managers resolving version ranges.

analyzed by
Leitwacht
first seen
Jul 16, 2026, 10:54 AM
analyzed
Jul 16, 2026, 10:54 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.