LWA-2026-10071 MAL-2026-11993 ↗ confirmed malware

@tuluax/errb@3.0.1

Malicious code in @tuluax/errb (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1195.002 · Compromise Software Supply Chain

Analysis

@tuluax/errb@3.0.1 is a trojanized clone of the legitimate `errno` package with a malicious install hook. The install script spawns a detached background `node index.js` process. That script AES-256-CBC-decrypts an embedded ciphertext to recover a remote URL, fetches it, and executes the returned body via eval() — a remote-code-execution dropper. At install time the process connects to backendapi-ddeaetc6gnfubvbf[.]a02[.]azurefd[.]net:443 and requests /api/health.php, receiving the payload to execute. The C2 host is backendapi-ddeaetc6gnfubvbf[.]a02[.]azurefd[.]net (Azure Front Door).

analyzed by
Leitwacht
first seen
Aug 4, 2026, 05:58 PM
analyzed
Aug 4, 2026, 05:58 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.