VYPR

npm · Malicious package advisory

Malware

@traktis/environment

GHSA-8w76-frwh-rcpm

Malicious code in @traktis/environment (npm)

Details

**Severity:** Critical

**Affected versions:** `= 99.99.1`

## Source: amazon-inspector (6b9bdabc95f4e8bc70e348557c1cae7d2447d9bd1405ac7a23945ded47ec04a8)
package.json declares preinstall and postinstall lifecycle scripts that invoke curl against the hardcoded cleartext endpoint http://tko.amgsec.com/depconf/traktis-environment/, sending the output of whoami, hostname, cwd, a timestamp, and a base64-encoded dump of CI/build environment variables matched by the pattern GITHUB_*, CI_PROJECT, JENKINS_URL, BUILD_URL, GITLAB_*, RUNNER_*, HOSTNAME, USER, HOME as query parameters. index.js is a 55-byte placeholder comment and author is listed as 'anonymous'; the manifest lifecycle scripts are the entire functional payload. The name occupies the @traktis scope at version 99.99.2, a version-inflation shape consistent with dependency-confusion resolution against an internal package of the same name. Installing the package on any developer workstation or CI runner automatically transmits build-system identity and any credential-shaped environment variables covered by the grep pattern to a third-party host over plain HTTP.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/77e1abe54c807a94ef54fde706a23385c94d9e9b/osv/malicious/npm/@traktis/environment/MAL-2026-16223.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/77e1abe54c807a94ef54fde706a23385c94d9e9b/osv/malicious/npm/@traktis/environment/MAL-2026-16223.json
- https://www.npmjs.com/package/@traktis/environment/v/99.99.1
- https://www.npmjs.com/package/@traktis/environment/v/99.99.2
- https://github.com/advisories/GHSA-8w76-frwh-rcpm

Compromised versions (1)

  • = 99.99.1

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.