LWA-2026-11350 confirmed malware

lodahsjs@1.0.0

Malicious code in lodahsjs (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1195.002 · Compromise Software Supply Chain

Analysis

The postinstall hook (scripts/postinstall.js) sends a host-fingerprint JSON body ({"platform":...}) to 193[.]70[.]34[.]101:20099/vote over HTTP. On Windows/WSL hosts it additionally downloads a second-stage binary from hxxps://github[.]com/beabraz1/qPzM50V1AKG0rVlH/releases/download/null/main[.]exe into %TEMP%\main.exe and launches it as a detached background process (or runs a bridge command via exec), executing a remote payload on the installer's machine.

analyzed by
Leitwacht
first seen
Aug 16, 2026, 02:52 AM
analyzed
Aug 16, 2026, 02:55 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.