@hibachi-xyz/config@99.0.0
Malicious code in @hibachi-xyz/config (npm)
Analysis
On require(), the package's index.js entry point harvests all environment variables matching credential-related patterns (KEY, SECRET, TOKEN, PASS, PRIV, SIGN, AWS, GITHUB, NPM, DOCKER, KUBE, CF_, and others), collects the hostname and username, runs 'whoami && id && cat /proc/1/cgroup' for container fingerprinting, and POSTs the collected data as JSON to jorijo[.]xyz on port 8443 at path /t over HTTPS (with certificate validation disabled). The version 99.0.0 on a scoped name is a dependency-confusion/version-squat pattern designed to be installed automatically by package managers resolving version ranges.
- analyzed by
- Leitwacht
- first seen
- Jul 16, 2026, 10:54 AM
- analyzed
- Jul 16, 2026, 10:54 AM
Related advisories
- @hibachi-xyz/types@99.0.0
- @hibachi-xyz/sdk@99.0.0
- @hibachi-xyz/ui@99.0.0
- @hibachi-xyz/common@99.0.0
- node-as-api@2.1.6
- typescript-api-node@2.1.6
- xxdxax@1.0.1
- react-hook-scripts@5.4.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.