LWA-2026-11327 confirmed malware

harmony-app-toolkit@21.0.0

Malicious code in harmony-app-toolkit (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall hook (node preinstall.js) reads a hex-encoded command from preinstall.json and executes it. The decoded command runs curl against hxxps://eoustf8gflamm91[.]m[.]pipedream[.]net with a POST body containing the output of whoami, pwd, hostname, and cat /etc/passwd, exfiltrating host identity and the system passwd file to the remote endpoint at install time.

analyzed by
Leitwacht
first seen
Aug 15, 2026, 01:58 PM
analyzed
Aug 15, 2026, 01:59 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.