LWA-2026-10656 confirmed malware

nice-utils-helper@1.0.0

Malicious code in nice-utils-helper (npm)

T1526 · Cloud Service DiscoveryT1082 · System Information Discovery

Analysis

The package's postinstall hook runs probe.js, which performs cloud-metadata reconnaissance. It sends HTTP GET requests to the /latest/meta-data/ endpoint of cloud metadata services (AWS 169[.]254[.]169[.]254, Aliyun 100[.]100[.]100[.]200, Tencent metadata[.]tencentyun[.]com and 169[.]254[.]0[.]23) and records each endpoint's reachability status (HTTP status code, timeout, or connection error) to local files named NCODE_META.txt and NCODE_POC_MARKER.txt written into the working directory and parent directories. This probes whether the host is a cloud instance with a reachable metadata service — a reconnaissance step that precedes cloud IAM-credential harvesting.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 07:46 PM
analyzed
Aug 6, 2026, 07:46 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.