LWA-2026-11725 confirmed malware

cbc97b7a@1.1787999998.0

Malicious code in cbc97b7a (npm)

T1059.004 · Unix ShellT1496 · Resource HijackingT1489 · Service StopT1070 · Indicator RemovalT1105 · Ingress Tool TransferT1082 · System Information Discovery

Analysis

The package's description field contains a base64-encoded shell script that deploys a Monero (XMRIG) cryptominer. On execution the script kills competing miner processes (syslog-ng, donat-level, stratum+tcp, cryptonight, randomx, kill_cryptojack, high-CPU processes), scrubs crontab entries and adds iptables DROP rules for known miner C2 IPs (95[.]85[.]237[.]226, 193[.]41[.]68[.]194, 95[.]85[.]237[.]149, 2[.]26[.]99[.]68, 210[.]195[.]19[.]39, 66[.]23[.]199[.]44, 45[.]94[.]31[.]89, 139[.]59[.]59[.]33, 154[.]89[.]152[.]115, 84[.]21[.]173[.]223, 142[.]132[.]131[.]238), patches /lib/systemd/cache/process-watcher to run xmrig with the attacker's pool wallet 883kAB7UfoJCKPzZAavUCHJdH4L2qVjqw4A79diUrFjBWBFrerhXP FbbUZnY2CemcUiBcLpAUz38vVYBbUqTHAgoAwgBCFH, replaces the pool user in /var/tmp/.odoo_pg_health.json, removes competing miner artifacts, and fetches a miner config from hxxps://github[.]com/alsat/config[.]json.

analyzed by
Leitwacht
first seen
Aug 29, 2026, 11:46 AM
analyzed
Aug 29, 2026, 11:48 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.