LWA-2026-10614 confirmed malware
hojamalo-scanner@1.0.0
Malicious code in hojamalo-scanner (npm)
T1059 · Command and Scripting InterpreterT1082 · System Information Discovery
Analysis
hojamalo-scanner is a web security scanner CLI. Its postinstall hook modifies the user's shell profile (.bashrc/.zshrc/.profile) and on Windows runs setx to add the npm global bin directory to PATH. The scanner probes target sites for exposed sensitive files (.env, .git/config, .aws/credentials, id_rsa, backup files) and enumerates subdomains via crt.sh certificate transparency logs.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 12:02 PM
- analyzed
- Aug 6, 2026, 12:03 PM
Related advisories
- streak-cache-map@1.0.0
- clients-structure@35.9.8
- cnb-cnb-core@35.2.7
- cobrowsing-cobrowsing-core@35.5.8
- ezdiscordbots@1.0.2
- cobrowsing-configs@35.7.5
- cobrowsing-decorators@35.2.9
- cobrowsing-exception-filter@35.8.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.