LWA-2026-11016 confirmed malware

kit-map-vim@1.0.0

Malicious code in kit-map-vim (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1555.003 · Credentials from Web BrowsersT1555.004 · Windows Credential ManagerT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1547.001 · Registry Run Keys / Startup FolderT1053.003 · CronT1090 · ProxyT1136 · Create Account

Analysis

kit-map-vim@1.0.0 ships a bundled ELF binary (dist/internal/calc-math.dat) that is a full remote-access trojan. Importing the package spawns the binary detached at load time. The implant provides a remote shell with in-memory (memfd) payload execution and shellcode download/execution, a reverse tunnel (RC2TUN), SOCKS/port-forwarding, and persistence via cron, .bashrc, and a systemd user service. It harvests SSH keys (~/.ssh id_*, authorized_keys, known_hosts, config, ssh-agent keys), browser credentials (Chrome/Chromium/Brave/Edge Login Data, Cookies, Local State; Firefox logins.json and key4.db), and database credentials (.pgpass, .my.cnf, DB configs and env vars). It can download and execute arbitrary URLs, load arbitrary shared libraries, create/enable system users, and exfiltrate files to litterbox.catbox.moe. C2 endpoint IP: 217[.]60[.]77[.]63; public-IP discovery via api[.]ipify[.]org.

analyzed by
Leitwacht
first seen
Aug 12, 2026, 01:42 AM
analyzed
Aug 12, 2026, 01:44 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.