LWA-2026-11079 confirmed malware

fmt-util-k7x2@1.0.0

Malicious code in fmt-util-k7x2 (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.005 · Cloud Instance Metadata APIT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook (setup.js) of this package performs network reconnaissance and exfiltration. On install it probes internal Twilio infrastructure endpoints (www[.]stage[.]twilio[.]com, code[.]hq[.]twilio[.]com, twilio[.]jfrog[.]io, artifacts[.]twilio[.]com) and the AWS EC2 instance metadata service (hxxp://169[.]254[.]169[.]254/latest/meta-data/), then sends the reachability results to the attacker-controlled endpoint hxxp://bintool[.]brkd[.]no/compat-check. The AWS metadata probe indicates attempted harvesting of cloud instance credentials. The package's declared purpose (string formatting utilities) is unrelated to this behaviour.

analyzed by
Leitwacht
first seen
Aug 12, 2026, 03:51 PM
analyzed
Aug 12, 2026, 03:51 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.