LWA-2026-11498 confirmed malware

modsync@5.0.2

Malicious code in modsync (npm)

T1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

modsync@5.0.2 is a trojanized clone of the pino logger that ships a 4.1MB obfuscated lib/config.js. When the module is loaded, the obfuscated code collects the host's hostname, OS version, platform, and username and POSTs them as JSON to 167[.]88[.]167[.]54:8087 at /api/log and /api/notify, and uploads a sysinfo.txt file (containing host, OS, username, platform, timestamp) via multipart/form-data to 167[.]88[.]167[.]54:8085 at /upload. The C2 requests carry a per-install Validation HMAC header and a numeric userkey. The package exfiltrates system information from the machine that installs it.

analyzed by
Leitwacht
first seen
Aug 19, 2026, 04:51 AM
analyzed
Aug 19, 2026, 04:53 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.