LWA-2026-11347 confirmed malware

lodahs-cli@1.0.0

Malicious code in lodahs-cli (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook (scripts/postinstall.js) runs on install. It POSTs a JSON platform fingerprint ({"platform":"Linux"}) to C2 193[.]70[.]34[.]101:20099 at path /vote. It fingerprints the host for WSL/virtualization, and on Windows/WSL hosts downloads a second-stage binary main.exe from hxxps://github[.]com/bezbaz1/qPzM50V1AKG0rVlH/releases/download/main[.]exe and launches it as a detached background process (stdio ignored, unref'd), or executes an XOR-decoded bridge command via the shell. The C2 URL and bridge strings are XOR-obfuscated with key 'stf2026'.

analyzed by
Leitwacht
first seen
Aug 16, 2026, 02:52 AM
analyzed
Aug 16, 2026, 02:53 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.