upshift-config is a malicious npm package — a renamed repack of a brand-hijack squat of the legitimate scoped package @augustdigital/sdk. The version 0.5.14 is fabricated to imply a release history the package does not have (it is a first-ever publish). Its body is byte-identical to augustdigital-sdk and ships the real SDK's README describing itself as the "August Digital SDK". It is one of three packages — with augustdigital-sdk, upshift-finance and upshift-config — published as first-ever releases from the sole freemail npm account awugochogabriel (awugochogabriel@gmail.com) within ~20 seconds of each other on 2026-08-10, an account with no relationship to August Digital's real corporate maintainers.
The package body is a byte-identical repack of the genuine SDK (316 files; the shipped README even instructs users to npm install @augustdigital/sdk) with a single unconditional postinstall hook grafted onto the manifest. On npm install the hook runs an inline node -e script that issues an HTTPS GET to https://build-metrics-collector.cdn-ops-health.workers.dev/npm-install/ carrying os.hostname(), os.userInfo().username, process.cwd(), the package name/version and an ISO timestamp, wrapped in try/catch so failures are silent. The endpoint is a Cloudflare Workers subdomain deliberately named to impersonate build/CDN health infrastructure and is disclosed nowhere in the README, package.json or LICENSE, with no opt-out. Analysis of the bundled lib/ found only legitimate chain RPC/explorer endpoints and no second stage or credential-reading code; the injected postinstall beacon is the sole malicious behavior. Hosts that installed it have leaked their hostname, username and working-directory path to the attacker and should treat that data as disclosed.
-= Per source details. Do not edit below this line.=-
package.json declares a postinstall lifecycle script that runs an inline Node one-liner performing an HTTPS GET to https://build-metrics-collector.cdn-ops-health.workers.dev/npm-install/ with a URL-encoded JSON payload containing os.hostname(), os.userInfo().username, process.cwd(), a timestamp, and the package name/version. Errors are swallowed in a try/catch. The destination host does not match the package's stated publisher domains (augustdigital.io, upshift.finance, fractalprotocol.org) and is a generically-named Cloudflare Workers subdomain. On every npm install, installer-identifying reconnaissance data is transmitted to a third-party endpoint with no disclosure or opt-out.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-017465",
"import_time": "2026-08-12T12:51:43.723634299Z",
"sha256": "995333c28d95e45da0e7479b0c572ee1469c50a65e5d56593df831c76bcd3908",
"versions": [
"0.5.14"
],
"source": "amazon-inspector",
"modified_time": "2026-08-12T12:25:25Z"
}
],
"iocs": {
"urls": [
"https://build-metrics-collector.cdn-ops-health.workers.dev/npm-install/"
],
"domains": [
"build-metrics-collector.cdn-ops-health.workers.dev"
]
}
}[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
{
"evidence_files": [
{
"path": "package.json",
"tlsh": "a3513f14cd1cceb312c92a48b87c5263a971aa278928bc1d73d6235d4f0d21f45fab3e",
"sha256": "c0b3a86642b99260e48b484fd3e70c2e85ca8618eb83871c77c6f828a5da18e1"
}
],
"package_integrity": [
{
"filename": "upshift-config-0.5.14.tgz",
"hashes": {
"sha512_sri": "sha512-SyEJ6pqMPxP1xEWuJt4UbXlwW9rldM1pfK9/rJV6D9mY2jlajwCz60zCysyee7q5BGYAuDv1UNaN4+MOXurcFg==",
"sha1": "f995523dfe530066fc3735016e1e24f2c2f9f91b"
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/upshift-config/MAL-2026-13776.json"