LWA-2026-10714 MAL-2026-13521 ↗ confirmed malware

@rbxst/services@1.0.756

Malicious code in @rbxst/services (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1059 · Command and Scripting Interpreter

Analysis

The package's postinstall hook (scripts/postinstall.js) is a Windows-targeted multi-stage dropper. On Windows installs it downloads a ZIP archive from hxxps://files[.]catbox[.]moe/rp8idk[.]zip into the temp directory, extracts it with PowerShell Expand-Archive, then launches a detached, hidden pythonw.exe process that runs an exec_.py script from the extracted archive, and finally deletes the ZIP. This downloads and executes an unknown remote payload at install time.

analyzed by
Leitwacht
first seen
Aug 7, 2026, 10:04 AM
analyzed
Aug 7, 2026, 10:04 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.