LWA-2026-10916 confirmed malware
@noobaihome/amis-simple-area-widget@1.0.0
Malicious code in @noobaihome/amis-simple-area-widget (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The package's preinstall hook (node ./scripts/install.js) performs a server-side request forgery probe and exfiltrates the result. On install it fetches the internal endpoint hxxp://bsrc-ssrf[.]n[.]baidu-int[.]com/bsrc_uid, then base64url-encodes the response body and sends it to the external callback server hxxp://49[.]232[.]169[.]67:43817/bsrc-r255?marker=BSRC_RCE_R255_7e49c2&uid=<encoded>. The package is disguised as a chart widget but runs this network probe automatically during installation.
- analyzed by
- Leitwacht
- first seen
- Aug 10, 2026, 05:42 AM
- analyzed
- Aug 10, 2026, 05:43 AM
Related advisories
- @noobaihome/amis-uni-area-widget@1.0.0
- hex-encode-utils@1.0.5
- @darshanpatel2608/cursor-dash@1.0.0
- simple-date-formatter-new-10@1.0.0
- cryptostock@1.0.0
- kit-map-streak@1.0.0
- global-intel@1.0.1
- map-streak-kit@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.