LWA-2026-11387 confirmed malware

sbirontime@1.0.0

Malicious code in sbirontime (npm)

T1059.007 · JavaScriptT1059.001 · PowerShellT1543.003 · Windows ServiceT1036.005 · Match Legitimate Resource Name or LocationT1562.001 · Disable or Modify ToolsT1136.001 · Local AccountT1078 · Valid AccountsT1082 · System Information Discovery

Analysis

The npm postinstall hook (elevated via UAC) installs a bundled VPN client and RDP Wrapper, then configures the host for covert remote access. It enables Remote Desktop on port 3389 with full shadow access without permission and Network Level Authentication disabled, creates or enables a local administrator account using a hardcoded password shipped in config.json, and registers a Windows service. It rewrites the PE version resources of the installed executables to masquerade as 'Service Host: Network Infrastructure Service' (svchost.exe) in Task Manager and Services, hides the installed folders and the created account from the sign-in screen, and stores the admin credentials in %ProgramData%\BikliWrapper\admin-credentials.json. No network C2 endpoint is used; access is via the enabled RDP listener and the hidden admin account.

analyzed by
Leitwacht
first seen
Aug 17, 2026, 04:14 AM
analyzed
Aug 17, 2026, 04:15 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.