LWA-2026-11380 confirmed malware

@evial/runtime-health@1.0.0

Malicious code in @evial/runtime-health (npm)

T1552.001 · Credentials In FilesT1005 · Data from Local SystemT1082 · System Information DiscoveryT1059.007 · JavaScript

Analysis

The postinstall hook executes a charcode-obfuscated bootstrap appended to a vendored lodash. On install it harvests cloud credentials from ~/.aws/credentials, ~/.aliyun/config.json, ~/.cos_credential, ~/.baidubce/credentials, ~/.ossutilconfig, ~/.docker/config.json, ~/.kube/config and ~/.npmrc, dumps the full environment and `id` output, and probes cloud metadata endpoints 169[.]254[.]169[.]254, 100[.]100[.]100[.]200, metadata[.]tencentyun[.]com and 169[.]254[.]80[.]80. The collected data is written to rt-probe.log and sysinfo.log in the package directory, /workspace, and parent directories.

analyzed by
Leitwacht
first seen
Aug 16, 2026, 07:28 PM
analyzed
Aug 16, 2026, 07:28 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.