appsignal@9999.0.0
Malicious code in appsignal (npm)
Analysis
A dependency-confusion package impersonating the real appsignal APM agent. Published at version 9999.0.0 to win dependency resolution. The preinstall hook (callback.js) collects the hostname, username, current working directory, npm registry URL, and a broad set of CI/CD environment variables (GITHUB_REPOSITORY, CI_PROJECT_PATH, TRAVIS_REPO_SLUG, CIRCLE_PROJECT_REPONAME, and others) and exfiltrates them via HTTP GET to 75[.]119[.]137[.]232:31337/depconfuse. This is a reconnaissance implant designed to identify high-value CI build environments for follow-on compromise.
- analyzed by
- Leitwacht
- first seen
- Aug 2, 2026, 07:32 PM
- analyzed
- Aug 2, 2026, 07:32 PM
Related advisories
- speaker_tagging_media_player@9999.0.0
- beaver-ui-breadcrumbs@0.0.2
- accounts-forms@0.0.2
- accounts-card-design-picker@0.0.2
- tinkoff-pfpa-tools@20.3.1
- tinkoff-boxy-desktop-features-banner@20.2.4
- tinkoff-statist-browser-typed-client-mb.reliability.android.events@20.5.4
- tinkoff-statist-browser-typed-client-cardsmobile.events.promotest@20.8.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.