LWA-2026-10848 confirmed malware

wsallin@1.0.0

Malicious code in wsallin (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1059 · Command and Scripting Interpreter

Analysis

wsallin is a WebSocket proxy server that, when run, connects to the publisher's gRPC server at nzag[.]faiz[.]us.kg:5555 and registers as a monitoring agent using hardcoded credentials. The agent reports host system information (OS, CPU, memory, disk, network) and opens a bidirectional IOStream that allows the server to push tasks and spawn an interactive remote shell on the host (via node-pty, or fallback to script/python3 pty), giving the server operator command execution on any machine running the package. It also POSTs the node subscription URL to oooo[.]serv00[.]net for keepalive.

analyzed by
Leitwacht
first seen
Aug 8, 2026, 04:06 PM
analyzed
Aug 8, 2026, 04:06 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.