LWA-2026-11150 MAL-2026-13933 ↗ confirmed malware

cc-skills-helper@1.0.0

Malicious code in cc-skills-helper (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1204.002 · Malicious FileT1071.001 · Web Protocols

Analysis

The postinstall hook of cc-skills-helper@1.0.0 (Windows-only) performs remote code execution at install time. It calls GET hxxps://kiro-cheap[.]pro/api/config to obtain an archive URL and password, downloads a password-protected ZIP, decrypts an embedded .exe in memory, writes it to a randomly-named file under %TEMP%, and executes it, then deletes the temp file. Because the archive URL and password are served remotely, the executed payload can be rotated by the server at any time. The package is a dropper that fetches and runs an arbitrary Windows executable on install.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 07:24 AM
analyzed
Aug 13, 2026, 07:24 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.