LWA-2026-7895 MAL-2026-12334 ↗ confirmed malware

ach-detail@99.0.1

Malicious code in ach-detail (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

The package runs a preinstall hook on install that beacons host metadata to a remote collector. It POSTs a JSON body containing the hostname, package name/version, Node.js version, platform, and timestamp to hxxps://callback[.]kuldeep[.]io/beacon (with an HTTP fallback to hxxp://callback[.]kuldeep[.]io/beacon). The package is published at version 99.0.1 on a name that collides with an internal package, and its README claims it is an authorized bug-bounty proof-of-concept; that claim is not independently verifiable and the beacon executes on every install regardless.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 11:45 AM
analyzed
Aug 4, 2026, 01:33 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.