Malicious code in notafollower1226 (npm)
The npm package notafollower1226 contains malicious code in its postinstall script that exfiltrates ECS container metadata and environment variables to an anonymous ngrok tunnel. The package has no legitimate functionality and serves only as a reconnaissance beacon targeting CI/build infrastructure.
- Disclosed
- Last updated
- Blast radius
- Any npm installation of notafollower1226 in CI/build environments or local development systems
- Ecosystems
- Attack vectors
- Affected entities
- notafollower1226npm package containing malicious postinstall script
The npm package notafollower1226 was identified as containing malicious code designed to execute automatically during npm installation via a postinstall script. Upon installation, the script queries the ECS container metadata endpoint to collect task ARN, container image list, and log group/stream configuration information.\n\nThe malicious script also enumerates process.env for environment variable keys matching patterns associated with ownership and authorship metadata (/owner|team|user|created|author|maintainer|contact/i), then exfiltrates this data via curl to a hardcoded anonymous ngrok tunnel at https://mourner-slot-explicit.ngrok-free.dev.\n\nThe package contains no other functionality consistent with a legitimate purpose. The use of an ephemeral ngrok-free.dev subdomain and the targeting of ECS metadata endpoints indicate this is a supply-chain reconnaissance attack focused on CI/build infrastructure. The incident was identified and credited to the OpenSSF malicious-packages repository.\n\nAffected users should immediately remove this package from their environments and audit any systems where it was installed for potential credential or metadata exposure.
Indicators of compromise
- Packages
- notafollower1226
- Domains
- mourner-slot-explicit.ngrok-free.dev
Remediation
- Immediately uninstall notafollower1226 from all npm environments
- Audit npm audit logs and CI/build logs for any installations of notafollower1226
- Review ECS container metadata and environment variables for potential exposure, particularly those containing credentials or ownership information
- Rotate any credentials or tokens that may have been present in environment variables during installation
- Monitor outbound network traffic to ngrok-free.dev domains for evidence of data exfiltration
- Implement npm package scanning and allowlisting policies to prevent installation of unknown or suspicious packages
- Review npm package dependencies to ensure notafollower1226 was not pulled in as a transitive dependency
Sources
- GitHub Advisory GHSA-5wr5-5c46-vj4q · GitHub Advisory Database
Cite this entry
"Malicious code in notafollower1226 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 14, 2026; last updated August 14, 2026. https://supplychainattack.org/incident/malicious-code-in-notafollower1226-npm-un99il
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in core-tailwindcss-utility (npm)
core-tailwindcss-utility, an npm package falsely advertised as a Tailwind CSS utility, contains malicious code that fetches and executes arbitrary Node.js code from a remote C2 server. The package includes suspicious dependencies for credential theft and remote communication.
npmCompromised package - containedcritical
Malicious code in bcc-design-icons (npm)
bcc-design-icons@9999.0.0 on npm contains malicious postinstall script that exfiltrates hostname and package name to attacker-controlled IP 91.201.215.48:8000. The package lacks expected icon-library functionality and exhibits characteristics of a dependency-confusion attack targeting internal/private npm installers.
npmDependency confusionCompromised package - activecritical
Malware in checkout-create-pos-order-am
Malware discovered in the npm package checkout-create-pos-order-am. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in chlklib
Malware was discovered in the npm package chlklib, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package