data-format-helper@1.0.1
Malicious code in data-format-helper (npm)
Analysis
The package data-format-helper@1.0.1 is a trojanized utility that exfiltrates environment credentials and system metadata on install. Its postinstall.js runs a 5-phase reconnaissance payload: (1) harvests GitHub CI environment variables (GITHUB_REPOSITORY, GITHUB_ACTOR, GITHUB_REF, GITHUB_TOKEN, GITHUB_WORKFLOW, RUNNER_NAME) plus hostname, user identity, OS details, and Docker status; (2) probes the internal Tencent domain tst[.]woa[.]com via DNS and HTTP; (3) scans all environment variables for patterns matching KEY, TOKEN, SECRET, CREDENTIAL, NPM_TOKEN, GITHUB_TOKEN, GH_TOKEN, AWS_ and other credential-bearing names, then base64-encodes and exfiltrates them; (4) collects sudo privileges, running processes, network interfaces, and routing tables; (5) probes cloud metadata endpoints for Tencent Cloud (metadata[.]tencentyun[.]com), AWS (169[.]254[.]169[.]254), Alibaba Cloud (100[.]100[.]100[.]200), and GCP (metadata.google.internal). All collected data is sent via HTTP GET to the C2 domain pzs5w7ntzhsnepwk564lyfdci3oucl0a[.]oastify[.]com. The package's index.js contains only harmless color-conversion helper functions as a decoy.
- analyzed by
- Leitwacht
- first seen
- Jul 28, 2026, 07:23 AM
- analyzed
- Jul 28, 2026, 07:28 AM
Related advisories
- color-convert-helper@1.0.0
- react-campaign-optimizer@1.0.0
- simple-date-formatter-new-7@1.0.0
- simple-date-formatter-new-6@1.0.0
- @adominadmininstr/fmt-date-helper@1.0.0
- @adominadmininstr/date-util-helper@1.0.0
- array-sort-helper@1.0.0
- style-class-utils@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.