LWA-2026-6848 MAL-2026-10704 ↗ confirmed malware

@across-toolkit/typescript-config@99.0.0

Malicious code in @across-toolkit/typescript-config (npm)

T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages

Analysis

@across-toolkit/typescript-config@99.0.0 is a dependency-confusion package impersonating the Across Protocol toolkit. On install, the postinstall.js hook harvests cloud metadata credentials from GCP (metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token) and AWS (169[.]254[.]169[.]254/latest/meta-data/iam/security-credentials/), reads local credential files (~/.aws/credentials, ~/.npmrc, ~/.ssh/id_rsa, ~/.config/gcloud/application_default_credentials.json, .env, .env.local, /proc/1/environ), dumps the entire process environment (including all API keys and tokens), and exfiltrates everything via HTTPS POST to webhook[.]site/a585f4ec-20f7-4bd1-bac7-f3e53799dc5f. A second payload in eslint-config/postinstall.js performs the same credential theft to webhook[.]site/12b523e2-ee58-4598-8fe1-bbf1f3999550.

analyzed by
Leitwacht
first seen
Jul 16, 2026, 12:48 PM
analyzed
Jul 16, 2026, 04:40 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.