Malicious code in @mrbenty8jf1p9y5/oidc-bind-canary (npm)
The npm package @mrbenty8jf1p9y5/oidc-bind-canary contained malicious code in its postinstall lifecycle script that exfiltrated data to an attacker-controlled Cloudflare tunnel by spoofing GitHub Dependabot traffic. The malicious script executed automatically during npm install, making it a critical supply chain attack.
- Disclosed
- Last updated
- Blast radius
- All npm users who installed the malicious package version(s)
- Ecosystems
- Attack vectors
- Affected entities
- @mrbenty8jf1p9y5/oidc-bind-canarynpm package containing malicious postinstall script
The npm package @mrbenty8jf1p9y5/oidc-bind-canary was found to contain malicious code embedded in its postinstall lifecycle script. When installed via npm, the script automatically issued an HTTPS request to a Cloudflare tunnel endpoint at wiki-shared-carlos-exempt.trycloudflare.com on the path /token-capture.
The attack employed sophisticated obfuscation techniques to evade detection. The request included a spoofed Host header set to dependabot-api.githubapp.com and disabled TLS certificate validation (rejectUnauthorized:false), making the malicious traffic appear as legitimate GitHub Dependabot API calls. This disguise was designed to blend in with normal development environment traffic.
The destination path name (/token-capture) and the mechanics of the attack indicate an install-time beacon to an attacker-controlled listener, firing automatically whenever the package was installed. This allowed the attacker to capture tokens or other sensitive data from the installer's machine.
The incident was identified and credited to the OpenSSF's malicious-packages repository, which tracks known malicious npm packages.
Indicators of compromise
- Packages
- @mrbenty8jf1p9y5/oidc-bind-canary
- Domains
- wiki-shared-carlos-exempt.trycloudflare.com
Remediation
- Immediately uninstall @mrbenty8jf1p9y5/oidc-bind-canary from all systems
- Audit npm install logs to identify when the package was installed and on which machines
- Rotate any credentials, tokens, or secrets that may have been exposed on affected machines
- Review network logs for outbound HTTPS connections to wiki-shared-carlos-exempt.trycloudflare.com
- Implement npm package scanning and verification in your CI/CD pipeline to detect malicious packages before installation
- Use npm audit and tools like Snyk to monitor for known malicious packages
- Consider using npm package lockfiles and integrity verification to prevent unexpected package installations
Sources
- GitHub Advisory GHSA-6frr-644f-4r3j · GitHub Advisory Database
Cite this entry
"Malicious code in @mrbenty8jf1p9y5/oidc-bind-canary (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 7, 2026; last updated August 7, 2026. https://supplychainattack.org/incident/malicious-code-in-mrbenty8jf1p9y5-oidc-bind-canary-npm-1jg17e
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in epic-common (npm)
The npm package epic-common was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.
npmCompromised package - containedcritical
Malware in a.poltoradnev-package-c
Malware was discovered in the npm package a.poltoradnev-package-c. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in envfile-sync-cli
Malware was discovered in the npm package envfile-sync-cli, providing full system compromise to any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in sui-gql-core
Malware was discovered in the npm package sui-gql-core. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package