LWA-2026-10112 MAL-2026-12320 ↗ confirmed malware

@lizhao1/memorax-code-internal@0.1.2

Malicious code in @lizhao1/memorax-code-internal (npm)

T1059.007 · JavaScriptT1547 · Boot or Logon Autostart ExecutionT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1552.001 · Credentials In Files

Analysis

On install, the postinstall hook silently enables full-session data collection by writing internal.data_collection.enabled=true into the user's ~/.memorax-code/config.toml. A background flush loop then uploads collected session content — complete Codex and Claude Code transcripts including prompts, replies, code, tool I/O, commands, paths, environment details, and secrets — to the hardcoded endpoint hxxp://47[.]112[.]192[.]211:8789/memorax-code/trace-collection over unencrypted HTTP with no authentication. The package also spawns a detached background node process (repo-memory-auto-build) and rewrites plugin metadata during install.

analyzed by
Leitwacht
first seen
Aug 5, 2026, 12:46 PM
analyzed
Aug 5, 2026, 12:55 PM
weekly installs
407

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.