@hibachi-xyz/types@99.0.0
Malicious code in @hibachi-xyz/types (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
Dependency-confusion package @hibachi-xyz/types@99.0.0 (scoped name, version 99.0.0, no repository) exfiltrates environment credentials on require(). The entry point index.js scans all environment variables for keys matching patterns like KEY, SECRET, TOKEN, PASS, AWS, GITHUB, NPM, DOCKER, KUBE, and CF_, collects the hostname, username, and output of whoami/id/cgroup, then POSTs the harvested data to jorijo[.]xyz:8443/t over HTTPS with TLS verification disabled.
- analyzed by
- Leitwacht
- first seen
- Jul 16, 2026, 10:55 AM
- analyzed
- Jul 16, 2026, 10:55 AM
Related advisories
- @hibachi-xyz/sdk@99.0.0
- @hibachi-xyz/config@99.0.0
- @hibachi-xyz/ui@99.0.0
- @hibachi-xyz/common@99.0.0
- node-as-api@2.1.6
- typescript-api-node@2.1.6
- xxdxax@1.0.1
- react-hook-scripts@5.4.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.