LWA-2026-11349 confirmed malware
commandor-core@1.0.0
Malicious code in commandor-core (npm)
T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The postinstall hook (scripts/postinstall.js) runs on install. It fingerprints the host (platform, architecture, Node version, WSL/virtualization detection) and POSTs the result as JSON to 193[.]70[.]34[.]101:20099/vote. It then downloads a remote binary from an XOR-obfuscated URL and executes it as a detached background process (stdio ignored), or on Windows/WSL runs a shell command via exec. The package is a 3-file tarball with no declared functionality.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 02:50 AM
- analyzed
- Aug 16, 2026, 02:53 AM
Related advisories
- ladash-cli@1.0.0
- comanderjs@1.0.0
- comander-cli@1.0.0
- chalk-es@1.0.0
- chalk-lib@1.0.0
- mutex-thread@1.3.0
- @hzero-front-ui/core@99.99.99
- datetime-fmt-xutil@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.