LWA-2026-11389 confirmed malware

runtime-health@1.0.1

Malicious code in runtime-health (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1547.001 · Registry Run Keys / Startup FolderT1053.003 · CronT1082 · System Information DiscoveryT1016 · System Network Configuration DiscoveryT1046 · Network Service DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1102 · Web ServiceT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook (scripts/bootstrap.js) executes a multi-stage attack on install. It enumerates the host for sandbox-escape conditions (capabilities, seccomp, cgroup, mounts, docker/containerd sockets, Kubernetes service-account token), then establishes persistence by writing a reverse-shell beacon to .beacon.js in the project root, rewriting the project's package.json to add prepare/prebuild/prelint hooks that re-run it, installing cron @reboot entries, appending a hook to /root/.bashrc, and spawning a detached setsid watchdog. The beacon opens a reverse shell to 159[.]75[.]160[.]206:4444 (bash -i, reconnect every 10s) and executes arbitrary commands. The payload also scans internal network ranges (10[.]100[.]0[.]46, 10[.]201[.]0[.]1, 10[.]100[.]16[.]43, 10[.]100[.]67[.]1, 10[.]100[.]67[.]124) across ports 80/443/5432/5433/8080/8443/3000/3001/9090/6379/2379/6443/10250/22, and brute-forces MCP endpoints on 10[.]100[.]0[.]46 (Host: mcp[.]miaoda[.]cn) while harvesting the MIAODA_SANDBOX_MCP_AUTHORIZATION_KEY and INTEGRATIONS_API_KEY environment variables. Results are written to rt3-probe.log, sysinfo3.log, and /tmp/beacon3.status.

analyzed by
Leitwacht
first seen
Aug 17, 2026, 08:46 AM
analyzed
Aug 17, 2026, 08:47 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.