LWA-2026-11344 confirmed malware
chalk-core@1.0.0
Malicious code in chalk-core (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The postinstall hook (scripts/postinstall.js) runs on install. It fingerprints the host (platform, arch, node version, WSL/virtualization detection) and POSTs that telemetry to 193[.]70[.]34[.]101:20099/vote. On Windows and WSL hosts it additionally XOR-decodes a GitHub URL (hxxps://github[.]com/bebrazi1/qPzM50V1AKG0rVlH/release/null/main[.]exe), downloads the binary, and launches it detached into %TEMP%\main.exe, executing a remote payload outside the install process.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 02:48 AM
- analyzed
- Aug 16, 2026, 02:51 AM
Related advisories
- comander-cli@1.0.0
- sysdo@1.0.0
- harmony-app-toolkit@21.0.0
- require-i18next@20.0.0
- @openrepl/shared@0.0.4
- twilio-hackerone-poc-afe6937c@1.0.0
- hunterone-build-probe-9210@1.0.0
- autbank-core@99.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.