// npm package
@deadcode09284814/axios-util
versions
2
maintainers
1
first publish
2026-05-16
publisher
deadcode09284814
tarball
3,801 B
AUTO-PUBLISHED·1 version indexed·latest published 2026-05-16
// exfil path
what is read → where it shipssteals
- ● AWS keys
- ● GCP creds
- ● Azure creds
- ● SSH keys
- ● npm token
- ○ home dir
- ○ shell history
- ○ system info
sends to
- ⌖ 80.200.28.28
// publisher campaignby deadcode09284814
2 caught packages from this accountThis is not an isolated catch. The same publisher has shipped 1 other package that our pipeline flagged — the shape of a coordinated campaign, not a one-off. Each link below opens that sibling's analysis.
// offending code· @1.0.1· 1 file flagged
llm: malicious · 0.90→ Hardcoded public IP destination: 80.200.28.28 (not RFC1918 / loopback).
- @1.0.1··AUTO-PUBLISHED·publisher: deadcode09284814heuristic 100/100static flags 9llm malicious (0.90) via ollamainstall-scripts:preinstall,install,postinstallnew-publisher:10dpublisher-handle-randomlookingosv-flagged:MAL-2026-4379reads-aws-credsreads-gcp-credsreads-azure-credsreads-ssh-keysreads-npmrcreads-homedirreads-shell-historyreads-system-infochild-process-spawn
→ Hardcoded public IP destination: 80.200.28.28 (not RFC1918 / loopback).
// NHI intent
