LWA-2026-11132 confirmed malware

@biklitime/biklimaster@1.1.6

Malicious code in @biklitime/biklimaster (npm)

T1136.001 · Local AccountT1078 · Valid AccountsT1562.001 · Disable or Modify ToolsT1112 · Modify RegistryT1552.001 · Credentials In FilesT1059.001 · PowerShell

Analysis

On install, this Windows-only package silently enables Remote Desktop on port 3389, installs the third-party RDP Wrapper tool to patch termsrv.dll, and creates or enables a hidden local administrator account (the built-in Administrator, or a new 'admin'/'user' account) using a hardcoded password shipped in the package's config.json. The account is added to the Administrators and Remote Desktop Users groups, hidden from the Windows sign-in screen, and its credentials are written to %ProgramData%\BikliWrapper\admin-credentials.json. Network Level Authentication is disabled and firewall rules are opened for port 3389. The result is persistent remote RDP access to the machine with a known password.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 02:56 AM
analyzed
Aug 13, 2026, 02:57 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.