@ks-radar/radar@21.0.0
Malicious code in @ks-radar/radar (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
The package runs a preinstall script that reads a hex-encoded command from a bundled JSON file, decodes it, and executes it. The decoded command uses curl to POST system information (whoami, current working directory, hostname) and the contents of /etc/passwd to a remote webhook endpoint at eobdzec83knbura[.]m[.]pipedream[.]net. This is a system-reconnaissance and data-exfiltration payload that runs at install time without the user's knowledge.
- analyzed by
- Leitwacht
- first seen
- Jul 25, 2026, 09:22 PM
- analyzed
- Jul 25, 2026, 09:23 PM
Related advisories
- basic-vite@1.0.0
- page-navigation@1.0.1
- xo-member-components@28.0.0
- merchantprefsservice-paypal@28.0.0
- identityauthorizationserv@28.0.0
- fundraiserservpp@1.9.0
- @kite-js-tools/core@1.0.0
- @cybs_forus/test@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.