LWA-2026-10473 MAL-2026-13357 ↗ confirmed malware

app-hsu-layer@2.1.6

Malicious code in app-hsu-layer (npm)

T1059.007 · JavaScriptT1098.004 · SSH Authorized KeysT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 ChannelT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

The postinstall hook executes a script that (1) recursively scans the working directory for credential/config files (id.json, config.toml, Config.toml, env, .env) and uploads each, prefixed with the OS username, to hxxp://95[.]216[.]118[.]146:3001/api/v1; and (2) fetches an SSH key and file-scan patterns from hxxp://170[.]205[.]31[.]203:3001/api/ssh-key, /api/scan-patterns and /api/block-patterns, then on Linux appends the attacker's SSH public key to ~/.ssh/authorized_keys and runs `sudo ufw enable` and `sudo ufw allow 22/tcp` to open SSH access, and finally scans the home directory (and Windows drives) for files matching the attacker-supplied patterns and batch-uploads them to hxxp://170[.]205[.]31[.]203:3001/api/v1. This installs a persistent SSH backdoor and exfiltrates local credential and configuration files to the two C2 hosts.

analyzed by
Leitwacht
first seen
Aug 5, 2026, 04:36 PM
analyzed
Aug 5, 2026, 04:38 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.