LWA-2026-11635 confirmed malware

model-poc-suhail@1.0.12

Malicious code in model-poc-suhail (npm)

T1059.007 · JavaScriptT1059.004 · Unix ShellT1071.001 · Web Protocols

Analysis

The package's postinstall hook runs poc.js, which opens a reverse shell: it spawns /bin/sh and pipes it to a TCP socket connected to 0[.]tcp[.]in[.]ngrok[.]io:19775, giving the remote operator an interactive shell on the installer's machine at install time.

analyzed by
Leitwacht
first seen
Aug 26, 2026, 06:33 AM
analyzed
Aug 26, 2026, 06:34 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.