LWA-2026-11002 confirmed malware

dakumangalsingh@1.0.0

Malicious code in dakumangalsingh (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1547.001 · Registry Run Keys / Startup FolderT1113 · Screen CaptureT1082 · System Information DiscoveryT1105 · Ingress Tool Transfer

Analysis

The npm package dakumangalsingh@1.0.0 runs a bundled Windows executable during installation. Its postinstall hook executes DakuMangalSingh/DakuMangalSingh.exe, a Java-packaged launcher that runs a bundled JAR (DakuMangalSingh/app/virus.jar) containing classes for device-ID fingerprinting, remote fetch/execution, robot/automation control, and screenshot capture (Fetch, DeviceId, RobotService, Screenshort, BatchExecutor, Executor, Main). The package also ships replicate.bat, which creates a shortcut to the executable and copies it into the Windows Startup folder (%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\DakuMangalSingh.lnk) to achieve persistence on every login, and cleanup.bat, a self-deleting cleanup script. The package bundles a full Java 20 runtime solely to run this payload. Installing this package on Windows executes the bundled malware and registers it to run at startup.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 08:55 PM
analyzed
Aug 11, 2026, 08:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.