Supply-chain threat intelligence

Incident detail

criticalnpm·malware·osv

Malicious code in @sudoughnym/enviro-demo (npm)

@sudoughnym/enviro-demo

Risk score

92

AI summary

Indexed incident for @sudoughnym/enviro-demo (npm).

Description

@sudoughnym/enviro-demo@99.99.99 ships preinstall.js and postinstall.js lifecycle scripts that run automatically on npm install. Both scripts collect host identifiers and environment metadata — os.hostname(), process.cwd(), pid, node version, platform, process.env.USER, the first ten environment variable names, and the total env count — and POST them as JSON to https://webhook.site/f83b073c-a04a-4ac5-8930-507051bd22f7, a third-party webhook capture service not associated with the package's stated publisher. The package version (99.99.99) and its own description identify it as a dependency-confusion proof-of-concept targeting an internal enviro package name; the inflated semver is intended to outrank private-registry versions so internal build systems resolve to this public package. Installer harm: any build or developer machine that resolves to this version leaks host identity and environment-variable layout (which can include secret-bearing variable names) to an attacker-controlled endpoint on every install.

Technical details

Affected versions

=99.99.99

Indicators

  • affected version=99.99.9975%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents