LWA-2026-10092 MAL-2026-12328 ↗ confirmed malware

@rentwise/common@1.0.36

Malicious code in @rentwise/common (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1102 · Web ServiceT1041 · Exfiltration Over C2 ChannelT1082 · System Information Discovery

Analysis

@rentwise/common@1.0.36 ships a hidden C2 implant appended to build/index.js. On load, the package decodes an obfuscated payload that queries public Ethereum JSON-RPC endpoints (1rpc[.]io/eth, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io) to read a transaction from a hardcoded address, derives two IPv4 addresses from the transaction's `to` field, and then spawns detached `node -e` processes that beacon to hxxp://<derived-ip>:443/0x/cls and /0x/ls, sending XOR-encoded payloads in an x-payload-b64 header. The implant establishes outbound connections to the derived C2 hosts over HTTP.

analyzed by
Leitwacht
first seen
Aug 5, 2026, 07:35 AM
analyzed
Aug 5, 2026, 07:41 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.