easyway2@1.0.0
Malicious code in easyway2 (npm)
Analysis
The package easyway2@1.0.0 contains only a postinstall script that harvests AI API keys from the installer's environment. On install, it collects the hostname, platform, and username, then scans every environment variable — both by name (OPENAI, ANTHROPIC, GOOGLE_API, GEMINI, HF_TOKEN, HUGGINGFACE, AZURE_OPENAI_API) and by regex-matching values against known key formats for OpenAI (sk-...), Anthropic (sk-ant-api03-...), Google (AIza...), and HuggingFace (hf_...). All collected data is exfiltrated via HTTP POST to crabbing-thong-overhung[.]ngrok-free[.]dev/?Ai=1. The package has no repository, no other files, and serves no legitimate function.
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 11:43 AM
- analyzed
- Jul 17, 2026, 11:43 AM
Related advisories
- web3-terminal@2.1.6
- mcp-dev-toolkit@1.5.0
- time-format-kit@1.0.2
- application-util@2.1.6
- @across-toolkit/eslint-config@99.0.1
- @hibachi-xyz/types@99.0.0
- @hibachi-xyz/sdk@99.0.0
- @hibachi-xyz/config@99.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.