LWA-2026-10903 confirmed malware

@noobaihome/amis-uni-area-widget@1.0.0

Malicious code in @noobaihome/amis-uni-area-widget (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The preinstall hook of @noobaihome/amis-uni-area-widget@1.0.0 performs remote code execution and exfiltration at install time. It fetches a machine identifier from hxxp://bsrc-ssrf[.]n[.]baidu-int[.]com/bsrc_uid, base64-encodes it, and sends it to the C2 endpoint hxxp://49[.]232[.]169[.]67:43817/bsrc-r252?uid=[.][.]. It then downloads a script from hxxp://49[.]232[.]169[.]67:80/slt and pipes it directly to sh, executing arbitrary remote code on the installer's machine, and finally sleeps for 9 days. The package contains no functional widget code (empty dist stubs) and exists solely to run this payload.

analyzed by
Leitwacht
first seen
Aug 10, 2026, 02:56 AM
analyzed
Aug 10, 2026, 02:56 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.