LWA-2026-10947 confirmed malware
freeai-proxy@1.0.0
Malicious code in freeai-proxy (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
The package's install hook (package.json "install": "node install.js") runs a shell command that downloads and executes a remote script from hxxps://freeai-proxy[.]pages[.]dev/install[.]sh via `curl -fsSL ... | bash` on macOS/Linux. This fetches and runs arbitrary remote code at install time from a non-standard host, with no way for the installer to inspect the payload before it executes.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 01:51 AM
- analyzed
- Aug 11, 2026, 01:51 AM
Related advisories
- vexium-kit@2.0.2
- process-live-log@11.5.2
- @sqlite-labs/nodesql@1.0.5
- safe-local-env-loader@1.0.0
- ventra-kit@1.0.2
- @sqlite-labs/createsql@1.0.1
- chai-as-reformed@1.2.0
- dayjs-advanced@1.2.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.