LWA-2026-11427 confirmed malware
dev-env-check@1.0.3
Malicious code in dev-env-check (npm)
T1195.002 · Compromise Software Supply ChainT1059.001 · PowerShellT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1204 · User Execution
Analysis
The postinstall hook of dev-env-check@1.0.3 runs a hidden Windows-only downloader. On win32 it invokes PowerShell (hidden, non-interactive) to download a remote binary from hxxps://updatesetup[.]online/click/update to %TEMP%\msedge_update.exe and then executes that downloaded file detached. The package's documented purpose is only benign development-environment checks (Node/npm/git version validation); the remote download-and-execute behaviour is concealed behind XOR-obfuscated strings and is not disclosed.
- analyzed by
- Leitwacht
- first seen
- Aug 18, 2026, 08:39 PM
- analyzed
- Aug 18, 2026, 08:39 PM
Related advisories
- bigops-cobrowsing-client@35.1.9
- codyx-ai@1.14.42
- sbirontime@1.0.0
- testingsmthb1g@1.0.0
- @biklitime/biklimaster@1.1.6
- @rblxts/services@1.6.0
- @solana-js/web3@1.91.3
- @coralxyz/anchor@0.30.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.