dakumangalsingh@1.0.0
Malicious code in dakumangalsingh (npm)
Analysis
The npm package dakumangalsingh@1.0.0 runs a bundled Windows executable during installation. Its postinstall hook executes DakuMangalSingh/DakuMangalSingh.exe, a Java-packaged launcher that runs a bundled JAR (DakuMangalSingh/app/virus.jar) containing classes for device-ID fingerprinting, remote fetch/execution, robot/automation control, and screenshot capture (Fetch, DeviceId, RobotService, Screenshort, BatchExecutor, Executor, Main). The package also ships replicate.bat, which creates a shortcut to the executable and copies it into the Windows Startup folder (%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\DakuMangalSingh.lnk) to achieve persistence on every login, and cleanup.bat, a self-deleting cleanup script. The package bundles a full Java 20 runtime solely to run this payload. Installing this package on Windows executes the bundled malware and registers it to run at startup.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 08:55 PM
- analyzed
- Aug 11, 2026, 08:56 PM
Related advisories
- safe-local-env-loader@1.0.0
- gpt-terminal-cli@1.0.0
- wormgpt-cli@1.0.1
- stellarfixer@1.0.0
- @types-beta/sdk@0.1.3
- system-performance-helper@1.0.1
- express-mongo-limit@2.0.1
- pinokio-redis@1.0.127
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.