LWA-2026-6877 MAL-2026-10769 ↗ confirmed malware

easyway2@1.0.0

Malicious code in easyway2 (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

The package easyway2@1.0.0 contains only a postinstall script that harvests AI API keys from the installer's environment. On install, it collects the hostname, platform, and username, then scans every environment variable — both by name (OPENAI, ANTHROPIC, GOOGLE_API, GEMINI, HF_TOKEN, HUGGINGFACE, AZURE_OPENAI_API) and by regex-matching values against known key formats for OpenAI (sk-...), Anthropic (sk-ant-api03-...), Google (AIza...), and HuggingFace (hf_...). All collected data is exfiltrated via HTTP POST to crabbing-thong-overhung[.]ngrok-free[.]dev/?Ai=1. The package has no repository, no other files, and serves no legitimate function.

analyzed by
Leitwacht
first seen
Jul 17, 2026, 11:43 AM
analyzed
Jul 17, 2026, 11:43 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.