LWA-2026-11327 confirmed malware
harmony-app-toolkit@21.0.0
Malicious code in harmony-app-toolkit (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel
Analysis
The package's preinstall hook (node preinstall.js) reads a hex-encoded command from preinstall.json and executes it. The decoded command runs curl against hxxps://eoustf8gflamm91[.]m[.]pipedream[.]net with a POST body containing the output of whoami, pwd, hostname, and cat /etc/passwd, exfiltrating host identity and the system passwd file to the remote endpoint at install time.
- analyzed by
- Leitwacht
- first seen
- Aug 15, 2026, 01:58 PM
- analyzed
- Aug 15, 2026, 01:59 PM
Related advisories
- tailwind-utility-kit@1.3.2
- hunterone-build-probe-9210@1.0.0
- sbironman@1.0.0
- autbank-core@99.0.0
- axios-fast@1.0.0
- meualelo@99.0.2
- alelo-auth@99.0.2
- alelo-api@99.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.