Malicious code in @shiftmarkets/shift-exchange-root (npm)
The npm package @shiftmarkets/shift-exchange-root versions 1.9.9, 2.9.9, and 3.9.9 contains malicious code in its postinstall script. This script collects detailed host information including hostname, username, sudo user, home directory, internal IP addresses, DNS domain, environment variable names filtered by credential-related keywords, and CI indicators. It then sends this data over unencrypted HTTP to an unaffiliated external IP address. The package's main functionality does not align with its name, and the script's comment misleadingly claims only non-sensitive telemetry is collected, contradicting the actual data gathered.
AI Analysis
Technical Summary
The @shiftmarkets/shift-exchange-root npm package in versions 1.9.9, 2.9.9, and 3.9.9 executes a postinstall hook that runs a reconnaissance script (dist/recon.js). This script collects extensive system and environment information, including host identity, internal network details, and environment variable names filtered by credential-related patterns. It exfiltrates this data via a POST request over cleartext HTTP to an external IP address (138.68.108.20) not affiliated with the package publisher. The main package exports trivial math functions unrelated to its name, indicating deceptive behavior. The script's header falsely claims only non-sensitive telemetry is collected, while in reality sensitive host and environment data is gathered and transmitted.
Potential Impact
The malicious postinstall script can lead to unauthorized disclosure of sensitive host and environment information, including internal network topology, user identities, and environment variable names that may hint at credentials or secrets. This data exposure can facilitate further targeted attacks or credential harvesting by adversaries controlling the external server. The use of unencrypted HTTP increases the risk of interception. The deceptive nature of the package may cause users to unknowingly install it, leading to compromise of their development or deployment environments.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing the affected versions (=1.9.9, =2.9.9, =3.9.9) of @shiftmarkets/shift-exchange-root. Audit existing installations for the presence of this package and remove it if found. Monitor for network connections to the IP address 138.68.108.20 and block it if possible. Prefer installing packages from trusted sources and verify package integrity before installation. Check the vendor or package repository for updates or advisories regarding this malicious behavior.
Malicious code in @shiftmarkets/shift-exchange-root (npm)
Description
The npm package @shiftmarkets/shift-exchange-root versions 1.9.9, 2.9.9, and 3.9.9 contains malicious code in its postinstall script. This script collects detailed host information including hostname, username, sudo user, home directory, internal IP addresses, DNS domain, environment variable names filtered by credential-related keywords, and CI indicators. It then sends this data over unencrypted HTTP to an unaffiliated external IP address. The package's main functionality does not align with its name, and the script's comment misleadingly claims only non-sensitive telemetry is collected, contradicting the actual data gathered.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @shiftmarkets/shift-exchange-root npm package in versions 1.9.9, 2.9.9, and 3.9.9 executes a postinstall hook that runs a reconnaissance script (dist/recon.js). This script collects extensive system and environment information, including host identity, internal network details, and environment variable names filtered by credential-related patterns. It exfiltrates this data via a POST request over cleartext HTTP to an external IP address (138.68.108.20) not affiliated with the package publisher. The main package exports trivial math functions unrelated to its name, indicating deceptive behavior. The script's header falsely claims only non-sensitive telemetry is collected, while in reality sensitive host and environment data is gathered and transmitted.
Potential Impact
The malicious postinstall script can lead to unauthorized disclosure of sensitive host and environment information, including internal network topology, user identities, and environment variable names that may hint at credentials or secrets. This data exposure can facilitate further targeted attacks or credential harvesting by adversaries controlling the external server. The use of unencrypted HTTP increases the risk of interception. The deceptive nature of the package may cause users to unknowingly install it, leading to compromise of their development or deployment environments.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing the affected versions (=1.9.9, =2.9.9, =3.9.9) of @shiftmarkets/shift-exchange-root. Audit existing installations for the presence of this package and remove it if found. Monitor for network connections to the IP address 138.68.108.20 and block it if possible. Prefer installing packages from trusted sources and verify package integrity before installation. Check the vendor or package repository for updates or advisories regarding this malicious behavior.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12509
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a735730bf8831d53913ceec
Added to database: 08/05/2026, 15:30:56 UTC
Last enriched: 08/05/2026, 15:42:17 UTC
Last updated: 09/07/2026, 23:17:46 UTC
Views: 49
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.