Malicious npm package published by threat actor "raya4321" as part of a coordinated typosquatting campaign impersonating Apple internal infrastructure services (authentication, PKI, telemetry, CloudKit, and cloud infrastructure). All packages in this campaign execute credential-theft payloads during npm installation via preinstall or postinstall lifecycle hooks.
Trigger: postinstall. Exfiltrates environment variables, SSH keys (~/.ssh), AWS credentials (~/.aws/credentials), and ~/.npmrc to https://franki.requestcatcher.com/applefullcreds via curl.
-= Per source details. Do not edit below this line.=-
The package apple-coredata-internal-service was found to contain malicious code.
{
"malicious-packages-origins": [
{
"versions": [
"1.1.0"
],
"import_time": "2026-04-30T22:23:09.368550826Z",
"modified_time": "2026-04-30T21:59:18Z",
"sha256": "ea2cc19050997a6df7c1c44b911046367e7424c12bb01206bcf608e4aa813d3f",
"source": "amazon-inspector"
}
]
}