LWA-2026-11614 confirmed malware

r4wk-book@2.2.2

Malicious code in r4wk-book (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071 · Application Layer Protocol

Analysis

The postinstall hook executes a bundled script that spawns a detached background process, waits 1-40 seconds, then opens a TCP connection to 172[.]16[.]42[.]138:1234 and pipes an interactive shell (/bin/sh -i on Unix, cmd.exe on Windows) over the socket — a reverse shell giving the remote host command execution on the installer's machine. The C2 address is stored base64-encoded in the script.

analyzed by
Leitwacht
first seen
Aug 25, 2026, 04:14 PM
analyzed
Aug 25, 2026, 04:14 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.