LWA-2026-11318 confirmed malware

sbman@1.0.0

Malicious code in sbman (npm)

T1059.007 · JavaScriptT1136.001 · Local AccountT1078 · Valid AccountsT1036.005 · Match Legitimate Resource Name or LocationT1562.001 · Disable or Modify ToolsT1543.003 · Windows ServiceT1070 · Indicator Removal

Analysis

The package's postinstall hook runs an installer that elevates to administrator and deploys a covert remote-access implant on Windows. It installs the RDP Wrapper tool (bundled RDPWInst.exe and rdpwrap.ini) to enable Remote Desktop with full shadow access without permission (Shadow=2), Network Level Authentication disabled, unlimited concurrent sessions and no session time limits, and adds firewall rules opening TCP/UDP 3389. It creates or enables a hidden built-in Administrator account using a hardcoded password shipped in config.json ("Hacker@1290") and hides that account from the Windows sign-in screen. It disguises the installed process and service as svchost.exe / "Service Host: Network Infrastructure Service" with Microsoft Corporation version metadata by rewriting the executable's resource section and compiling a C# launcher, and hides the install folders while restricting their ACLs to SYSTEM and Administrators. The configured administrator password is also written to %ProgramData%\BikliWrapper\admin-credentials.json.

analyzed by
Leitwacht
first seen
Aug 15, 2026, 09:07 AM
analyzed
Aug 15, 2026, 09:08 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.