LWA-2026-7597 MAL-2026-12512 ↗ confirmed malware

appsignal@9999.0.0

Malicious code in appsignal (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

A dependency-confusion package impersonating the real appsignal APM agent. Published at version 9999.0.0 to win dependency resolution. The preinstall hook (callback.js) collects the hostname, username, current working directory, npm registry URL, and a broad set of CI/CD environment variables (GITHUB_REPOSITORY, CI_PROJECT_PATH, TRAVIS_REPO_SLUG, CIRCLE_PROJECT_REPONAME, and others) and exfiltrates them via HTTP GET to 75[.]119[.]137[.]232:31337/depconfuse. This is a reconnaissance implant designed to identify high-value CI build environments for follow-on compromise.

analyzed by
Leitwacht
first seen
Aug 2, 2026, 07:32 PM
analyzed
Aug 2, 2026, 07:32 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.