LWA-2026-11376 confirmed malware

@evial/runtime-utils@1.0.0

Malicious code in @evial/runtime-utils (npm)

T1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1059.007 · JavaScript

Analysis

The postinstall hook (scripts/postinstall.js) runs system-recon commands (id, whoami, hostname, pwd, uname -a) and then dumps the full process environment, including credential-bearing variables and their values, into a log file written to the workspace root and /workspace/runtime-snapshot.log. The package's main module is an inert stub exporting only its name and version, so the sole executable behaviour is this environment/credential harvest. No network exfiltration endpoint is used; the collected environment is written to local log files.

analyzed by
Leitwacht
first seen
Aug 16, 2026, 06:43 PM
analyzed
Aug 16, 2026, 06:43 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.