LWA-2026-10845 confirmed malware
@rblxts/services@1.6.0
Malicious code in @rblxts/services (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.001 · PowerShellT1105 · Ingress Tool TransferT1053 · Scheduled Task/Job
Analysis
The postinstall hook (scripts/postinstall.js) is a Windows-only dropper. On Windows installs it creates a random directory under %LOCALAPPDATA%\Microsoft, downloads a ZIP archive from hxxps://maxls[.]catch[.]co/Yarbot/gwgw6ai56aXA, extracts it with PowerShell (Expand-Archive), and launches pythonw.exe exec_.py as a detached background process before deleting the archive. The second-stage payload is fetched from the remote host and executed without the installer's knowledge. All strings in the hook are hex-escaped to hide the download URL and commands.
- analyzed by
- Leitwacht
- first seen
- Aug 8, 2026, 02:56 PM
- analyzed
- Aug 8, 2026, 02:57 PM
Related advisories
- streak-map-kit@1.0.0
- streak-kit-map@1.0.0
- streak-map-cache@1.0.0
- streak-cache-map@1.0.0
- dolyame-ui-flag@35.7.6
- streak-calc-metrics@1.0.0
- streak-calc-math@1.0.0
- streak-math-calc@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.