LWA-2026-11635 confirmed malware
model-poc-suhail@1.0.12
Malicious code in model-poc-suhail (npm)
T1059.007 · JavaScriptT1059.004 · Unix ShellT1071.001 · Web Protocols
Analysis
The package's postinstall hook runs poc.js, which opens a reverse shell: it spawns /bin/sh and pipes it to a TCP socket connected to 0[.]tcp[.]in[.]ngrok[.]io:19775, giving the remote operator an interactive shell on the installer's machine at install time.
- analyzed by
- Leitwacht
- first seen
- Aug 26, 2026, 06:33 AM
- analyzed
- Aug 26, 2026, 06:34 AM
Related advisories
- internallib_v902@1.2.1
- @hzero-front-ui/cfg@99.99.99
- @hzero-front-ui/hzero-ui@99.99.99
- simple-date-formatter-new-9@1.0.0
- dolyame-boxy-desktop-bnpl-text-block@35.9.7
- bnpl-blocks-independent-bnpl-documents@35.6.6
- devplatform-api-v2-resources-metadata@35.7.7
- bnpl-blocks-atom-bnpl-dangerously-html@35.2.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.