LWA-2026-10711 confirmed malware

@fedfub/string-utils@1.0.0

Malicious code in @fedfub/string-utils (npm)

T1059.007 · JavaScriptT1195.002 · Compromise Software Supply ChainT1082 · System Information DiscoveryT1005 · Data from Local SystemT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1053.005 · Scheduled TaskT1053.003 · Cron

Analysis

The postinstall hook executes a bundled script that acts as a self-propagating implant. On install it harvests environment variables matching KEY/SECRET/TOKEN/PASS/AWS/JWT/STRIPE/PAYPAL/DB_/DATABASE/REDIS/MONGO, recursively reads source files (.js, .ts, .py, .go, .rs, .java, .c, .cpp, .h, .cs, .rb, .php) from the working directory, and reads SSH keys from ~/.ssh, then POSTs all collected data to 73[.]218[.]105[.]44:8080/collect. It self-propagates by publishing a <dependency>-patch package (version 99.0.0) containing the same payload for every dependency of the current project, and injects a dependency into package.json files across the home directory. It installs persistence via a scheduled task (Windows) or a @reboot cron entry (Linux). It beacons every 30 seconds to 73[.]218[.]105[.]44:8080/cmd?id=<id> and executes returned commands, posting command output to /result.

analyzed by
Leitwacht
first seen
Aug 7, 2026, 08:39 AM
analyzed
Aug 7, 2026, 08:40 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.