LWA-2026-10904 confirmed malware

neverthrow-js@2.0.0

Malicious code in neverthrow-js (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

The postinstall hook (dist/install.js) of neverthrow-js@2.0.0 fetches a remote payload and executes it. It constructs the URL hxxps://ecoferros[.]com/wp-content/plugins/elementor/modules/dev-tools/index[.]php?req=verify from obfuscated string fragments, downloads the response, base64-decodes it, and runs it via new Function with the require function passed in — executing arbitrary remote code at install time. The payload is served remotely rather than shipped in the package, and the hook is time-gated to activate after 2026-08-11 02:00:00 GMT. C2 host: ecoferros[.]com.

analyzed by
Leitwacht
first seen
Aug 10, 2026, 02:55 AM
analyzed
Aug 10, 2026, 02:55 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.