LWA-2026-6844 MAL-2026-10715 ↗ confirmed malware

@hibachi-xyz/types@99.0.0

Malicious code in @hibachi-xyz/types (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Dependency-confusion package @hibachi-xyz/types@99.0.0 (scoped name, version 99.0.0, no repository) exfiltrates environment credentials on require(). The entry point index.js scans all environment variables for keys matching patterns like KEY, SECRET, TOKEN, PASS, AWS, GITHUB, NPM, DOCKER, KUBE, and CF_, collects the hostname, username, and output of whoami/id/cgroup, then POSTs the harvested data to jorijo[.]xyz:8443/t over HTTPS with TLS verification disabled.

analyzed by
Leitwacht
first seen
Jul 16, 2026, 10:55 AM
analyzed
Jul 16, 2026, 10:55 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.