LWA-2026-10845 confirmed malware

@rblxts/services@1.6.0

Malicious code in @rblxts/services (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.001 · PowerShellT1105 · Ingress Tool TransferT1053 · Scheduled Task/Job

Analysis

The postinstall hook (scripts/postinstall.js) is a Windows-only dropper. On Windows installs it creates a random directory under %LOCALAPPDATA%\Microsoft, downloads a ZIP archive from hxxps://maxls[.]catch[.]co/Yarbot/gwgw6ai56aXA, extracts it with PowerShell (Expand-Archive), and launches pythonw.exe exec_.py as a detached background process before deleting the archive. The second-stage payload is fetched from the remote host and executed without the installer's knowledge. All strings in the hook are hex-escaped to hide the download URL and commands.

analyzed by
Leitwacht
first seen
Aug 8, 2026, 02:56 PM
analyzed
Aug 8, 2026, 02:57 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.