loadashjs@1.0.0
Malicious code in loadashjs (npm)
Analysis
loadashjs@1.0.0 is a typosquat of lodash whose postinstall hook (scripts/postinstall.js) runs on install. It fingerprints the host (platform, architecture, WSL detection via /proc/version and WSL env vars) and POSTs a JSON platform beacon to 193[.]70[.]34[.]101:20099/vote. On Windows and WSL hosts it additionally downloads a second-stage binary from hxxps://github[.]com/beebraz1/qPzM50V1AKG0rVlH/releases/download/null/main[.]exe into the TEMP directory and executes it as a detached background process (or via a shell bridge command on WSL), enabling remote code execution on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 02:52 AM
- analyzed
- Aug 16, 2026, 02:53 AM
Related advisories
- lodahs-cli@1.0.0
- commandor-core@1.0.0
- ladash-cli@1.0.0
- comanderjs@1.0.0
- comander-cli@1.0.0
- chalk-es@1.0.0
- chalk-lib@1.0.0
- mutex-thread@1.3.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.