LWA-2026-7607 MAL-2026-12435 ↗ confirmed malware

sc-geeksquad-core@9999.0.0

Malicious code in sc-geeksquad-core (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Dependency-confusion package with a preinstall hook that exfiltrates system and CI/CD environment metadata. The preinstall script (callback.js) collects the hostname, username, current working directory, npm registry URL, and CI/CD environment variables (GITHUB_REPOSITORY, CI_PROJECT_PATH, BUILD_REPOSITORY_NAME, BITBUCKET_REPO_FULL_NAME, TRAVIS_REPO_SLUG, DRONE_REPO, BUILDKITE_PIPELINE_SLUG, CIRCLE_PROJECT_REPONAME, JOB_NAME) and sends them via HTTP GET to 75[.]119[.]137[.]232:31337/depconfuse. The package has no functional code (index.js exports an empty object) and uses an inflated version number (9999.0.0) to take priority over any legitimate internal package with the same name.

analyzed by
Leitwacht
first seen
Aug 2, 2026, 07:33 PM
analyzed
Aug 2, 2026, 07:36 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.