blots@2.1.0
Malicious code in blots (npm)
T1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The package blots@2.1.0 contains no source code — only a package.json with preinstall and postinstall hooks. Both hooks execute a curl command that sends the installer's username, hostname, current working directory, and timestamp to a webhook[.]site endpoint (UUID: d80b4602-8a87-4693-8510-6ff77c62788e). This is host reconnaissance and beaconing at install time, exfiltrating system metadata to an anonymous webhook service commonly abused for command-and-control.
- analyzed by
- Leitwacht
- first seen
- Jul 28, 2026, 01:10 PM
- analyzed
- Jul 28, 2026, 01:10 PM
Related advisories
- @apexfnd/apex@1.0.1
- n8n-nodes-quick-utils@1.0.0
- n8n-nodes-task-runner@1.0.0
- n8n-nodes-devops-utils@1.0.0
- time-format-kit@1.0.2
- string-formatter-pro@1.0.0
- code-formatter-setup@1.0.0
- node-sysmon-native@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.