LWA-2026-11364 confirmed malware

comand@1.0.0

Malicious code in comand (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook (scripts/postinstall.js) beacons host platform metadata to 193[.]70[.]34[.]101:20099 via HTTP POST to /vote, and on Windows/WSL hosts downloads a native binary from hxxps://github[.]com/beabraz1/qPzM50V1AKG0rVlH/releases/download/null/main[.]exe into the temp directory as main.exe and executes it detached (backgrounded, hidden window). On WSL it runs a decoded bridge command via exec() to install the same addon. The binary URL is XOR-obfuscated in the script. The package performs host fingerprinting (WSL detection via /proc/version and kernel osrelease) before beaconing.

analyzed by
Leitwacht
first seen
Aug 16, 2026, 02:50 AM
analyzed
Aug 16, 2026, 02:51 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.