toll_free@1.0.1
Malicious code in toll_free (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
toll_free@1.0.1 contains no executable code — only a package.json with preinstall and postinstall hooks that curl a webhook[.]site URL, exfiltrating the installer's username (whoami), hostname, current working directory, and a timestamp. The curl output is discarded and errors suppressed, confirming the sole purpose is reconnaissance and beaconing, not installation. The exfiltration target is webhook[.]site (a webhook testing service commonly abused by malware for C2 callback collection).
- analyzed by
- Leitwacht
- first seen
- Jul 28, 2026, 01:00 PM
- analyzed
- Jul 28, 2026, 01:00 PM
Related advisories
- @adominadmininstr/fmt-date-helper@1.0.0
- @adominadmininstr/date-util-helper@1.0.0
- array-sort-helper@1.0.0
- json-to-table-util@1.0.0
- style-class-utils@1.0.0
- text-line-parser@1.0.0
- csv-parser-helper@1.0.0
- num-format-helper@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.