LWA-2026-11376 confirmed malware
@evial/runtime-utils@1.0.0
Malicious code in @evial/runtime-utils (npm)
T1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1059.007 · JavaScript
Analysis
The postinstall hook (scripts/postinstall.js) runs system-recon commands (id, whoami, hostname, pwd, uname -a) and then dumps the full process environment, including credential-bearing variables and their values, into a log file written to the workspace root and /workspace/runtime-snapshot.log. The package's main module is an inert stub exporting only its name and version, so the sole executable behaviour is this environment/credential harvest. No network exfiltration endpoint is used; the collected environment is written to local log files.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 06:43 PM
- analyzed
- Aug 16, 2026, 06:43 PM
Related advisories
- @evial/runtime-health@1.0.0
- @evial/init-helper-djkwt@1.0.0
- colorpicker-ui@1.2.6
- harmony-app-toolkit@21.0.0
- tailwind-utility-kit@1.3.2
- hunterone-build-probe-9210@1.0.0
- sbironman@1.0.0
- autbank-core@99.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.