LWA-2026-10916 confirmed malware

@noobaihome/amis-simple-area-widget@1.0.0

Malicious code in @noobaihome/amis-simple-area-widget (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall hook (node ./scripts/install.js) performs a server-side request forgery probe and exfiltrates the result. On install it fetches the internal endpoint hxxp://bsrc-ssrf[.]n[.]baidu-int[.]com/bsrc_uid, then base64url-encodes the response body and sends it to the external callback server hxxp://49[.]232[.]169[.]67:43817/bsrc-r255?marker=BSRC_RCE_R255_7e49c2&uid=<encoded>. The package is disguised as a chart widget but runs this network probe automatically during installation.

analyzed by
Leitwacht
first seen
Aug 10, 2026, 05:42 AM
analyzed
Aug 10, 2026, 05:43 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.