LWA-2026-11345 confirmed malware
ladash-cli@1.0.0
Malicious code in ladash-cli (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer
Analysis
The postinstall hook of ladash-cli (a typosquat of lodash) beacons the installer's platform/arch/node-version fingerprint to a hardcoded C2 at 193[.]70[.]34[.]101:20099 via HTTP POST to /vote. On Windows and WSL hosts it additionally downloads a second-stage binary main.exe from hxxps://github[.]com/beabraz1/qPzM50V1AKG0rVlH/release/download/main[.]exe into %TEMP% and launches it as a detached background process. The C2 host, port, and download URL are XOR-obfuscated in the script.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 02:52 AM
- analyzed
- Aug 16, 2026, 02:53 AM
Related advisories
- comanderjs@1.0.0
- comander-cli@1.0.0
- chalk-es@1.0.0
- chalk-lib@1.0.0
- mutex-thread@1.3.0
- @hzero-front-ui/core@99.99.99
- datetime-fmt-xutil@1.0.0
- check-audit@99.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.