ach-detail@99.0.1
Malicious code in ach-detail (npm)
Analysis
The package runs a preinstall hook on install that beacons host metadata to a remote collector. It POSTs a JSON body containing the hostname, package name/version, Node.js version, platform, and timestamp to hxxps://callback[.]kuldeep[.]io/beacon (with an HTTP fallback to hxxp://callback[.]kuldeep[.]io/beacon). The package is published at version 99.0.1 on a name that collides with an internal package, and its README claims it is an authorized bug-bounty proof-of-concept; that claim is not independently verifiable and the beacon executes on every install regardless.
- analyzed by
- Leitwacht
- first seen
- Aug 4, 2026, 11:45 AM
- analyzed
- Aug 4, 2026, 01:33 PM
Related advisories
- tailwind-anime@1.1.0
- bigops-call-history@35.8.9
- bigops-chats@35.9.6
- bigops-header-tabs@35.8.2
- bigops-customer@35.1.1
- bigops-auth-provider-interceptor@35.8.3
- bigops-info-notices@35.9.8
- bigops-chat-files-hub-client@35.4.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.