LWA-2026-11343 confirmed malware

comanderjs@1.0.0

Malicious code in comanderjs (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information Discovery

Analysis

The postinstall hook (scripts/postinstall.js) runs on install. It fingerprints the host (platform, architecture, Node version, WSL/virtualization detection via /proc/version) and POSTs the platform label as JSON to 193[.]70[.]34[.]101:20099/vote. On Windows or WSL hosts it then downloads a second-stage binary from hxxps://github[.]com/bebraz1/qPzM50V1AKG0rVlH/releases/download/null/main[.]exe into the temp directory and executes it as a detached background process (spawn with detached:true, stdio ignored, unref'd), or runs a bridge command via exec. The C2 endpoint is 193[.]70[.]34[.]101:20099.

analyzed by
Leitwacht
first seen
Aug 16, 2026, 02:49 AM
analyzed
Aug 16, 2026, 02:51 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.