LWA-2026-10947 confirmed malware

freeai-proxy@1.0.0

Malicious code in freeai-proxy (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

The package's install hook (package.json "install": "node install.js") runs a shell command that downloads and executes a remote script from hxxps://freeai-proxy[.]pages[.]dev/install[.]sh via `curl -fsSL ... | bash` on macOS/Linux. This fetches and runs arbitrary remote code at install time from a non-standard host, with no way for the installer to inspect the payload before it executes.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 01:51 AM
analyzed
Aug 11, 2026, 01:51 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.