LWA-2026-11342 confirmed malware

comander-cli@1.0.0

Malicious code in comander-cli (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook (scripts/postinstall.js) runs on install and beacons host metadata to a remote C2: it POSTs a JSON body {"platform":<os>} to 193[.]70[.]34[.]101:20099/vote. It fingerprints the host (node version, architecture, platform, and WSL/virtualization detection via /proc/version and /proc/sys/kernel/osrelease). On Windows and WSL hosts it downloads a second-stage binary from hxxps://github[.]com/bezzaz1/qPzM50V1AKG0rVlH/releases/download/main[.]exe, writes it to C:\Temp\main.exe, and launches it as a detached background process (or via a shell bridge command on WSL). The downloaded binary is executed without inspection.

analyzed by
Leitwacht
first seen
Aug 16, 2026, 02:49 AM
analyzed
Aug 16, 2026, 02:51 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.