lodhash-cli@1.0.0
Malicious code in lodhash-cli (npm)
Analysis
The postinstall hook (scripts/postinstall.js) of lodhash-cli fingerprints the host (platform, architecture, Node version, WSL detection) and POSTs the platform label to 193[.]70[.]34[.]101:20099/vote. On Windows and WSL it decodes an XOR-obfuscated URL and downloads a native binary main.exe from hxxps://github[.]com/bebrazi1/qzM50V1AKG0rVlH/releases/download/null/main[.]exe into the TEMP directory, then launches it as a detached background process; on WSL it additionally runs a decoded bridge script via exec. The package is a typosquat of lodash with no declared functionality.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 02:52 AM
- analyzed
- Aug 16, 2026, 02:53 AM
Related advisories
- chalk-core@1.0.0
- comander-cli@1.0.0
- sysdo@1.0.0
- harmony-app-toolkit@21.0.0
- require-i18next@20.0.0
- @openrepl/shared@0.0.4
- twilio-hackerone-poc-afe6937c@1.0.0
- hunterone-build-probe-9210@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.