LWA-2026-11281 confirmed malware

sbironman@1.0.0

Malicious code in sbironman (npm)

T1059.007 · JavaScriptT1543.003 · Windows ServiceT1036 · MasqueradingT1562.001 · Impair DefensesT1070 · Indicator RemovalT1136.001 · Local AccountT1552.001 · Credentials In Files

Analysis

The npm postinstall hook requests Windows administrator approval, then silently installs a bundled remote-access tool and configures the host for covert remote access. It installs a WireGuard-based overlay/VPN CLI and RDP Wrapper, then disguises the installed process and Windows service as a native "Service Host: Network Infrastructure Service" (svchost.exe) by rewriting the executable's version resources to impersonate Microsoft Corporation, compiling a C# forwarder that spawns the real service binary, renaming the service display name to a generic network-infrastructure description, and removing the application's Start-menu/App-Paths registry entries. It hides all installed folders (Program Files\Bikli, Program Files\RDP Wrapper, ProgramData\BikliWrapper) using hidden+system attributes and ACLs restricted to SYSTEM and Administrators. It enables Remote Desktop on TCP 3389 with Network Level Authentication disabled and full shadow access without permission, unlimited concurrent sessions, and no idle/connection time limits, and opens inbound firewall rules for RDP. It creates or enables a hidden local administrator account (the built-in Administrator, else 'admin' or 'user') with a hardcoded password shipped in the package's config.json, adds it to the Administrators and Remote Desktop Users groups, stores the credentials in C:\ProgramData\BikliWrapper\admin-credentials.json, and hides the account's profile folder. The result is a persistent, disguised remote-access backdoor with a known administrator credential.

analyzed by
Leitwacht
first seen
Aug 14, 2026, 04:12 PM
analyzed
Aug 14, 2026, 04:13 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.