LWA-2026-11427 confirmed malware

dev-env-check@1.0.3

Malicious code in dev-env-check (npm)

T1195.002 · Compromise Software Supply ChainT1059.001 · PowerShellT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1204 · User Execution

Analysis

The postinstall hook of dev-env-check@1.0.3 runs a hidden Windows-only downloader. On win32 it invokes PowerShell (hidden, non-interactive) to download a remote binary from hxxps://updatesetup[.]online/click/update to %TEMP%\msedge_update.exe and then executes that downloaded file detached. The package's documented purpose is only benign development-environment checks (Node/npm/git version validation); the remote download-and-execute behaviour is concealed behind XOR-obfuscated strings and is not disclosed.

analyzed by
Leitwacht
first seen
Aug 18, 2026, 08:39 PM
analyzed
Aug 18, 2026, 08:39 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.