LWA-2026-11274 confirmed malware

biklitool@1.1.11

Malicious code in biklitool (npm)

T1059.007 · JavaScriptT1136.001 · Local AccountT1078.003 · Local AccountsT1112 · Modify RegistryT1562.001 · Disable or Modify Tools

Analysis

The package's postinstall hook enables Remote Desktop on port 3389, opens inbound firewall rules, disables Network Level Authentication, and enables full RDP shadowing without permission. It then creates a hidden local administrator account (the built-in Administrator, or a new 'admin'/'user' account) using a hardcoded administrator password shipped in the package's config.json, and hides the account from the Windows sign-in screen. The configured credentials are also written to %ProgramData%\BikliWrapper\admin-credentials.json. Installing the package leaves the machine with a hidden admin account whose password is publicly known and Remote Desktop exposed with authentication weakened, providing persistent remote access with known credentials.

analyzed by
Leitwacht
first seen
Aug 14, 2026, 08:07 AM
analyzed
Aug 14, 2026, 08:08 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.