LWA-2026-11755 MAL-2026-15632 ↗ confirmed malware

node-request-utils@1.0.0

Malicious code in node-request-utils (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1547.001 · Registry Run Keys / Startup FolderT1053.005 · Scheduled TaskT1562.001 · Disable or Modify ToolsT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1497 · Virtualization/Sandbox Evasion

Analysis

The postinstall hook runs a Windows-only dropper. On install it fingerprints the host (exits on CI environments, low CPU/RAM, or sandbox-related usernames/hostnames), then downloads a second-stage payload from hxxps://limbomail[.]com/api/attachment/l4TIRPOsaUxR[.]_603-vhKDRdgKl3RalN_TVUZYGPsJy2Y/all[.]js and writes it as winsvc.js into hidden directories under %APPDATA%\Microsoft\Windows (WinSxS\Backup, Themes, Caches) or %TEMP%\MicrosoftEdge. It installs persistence through a VBS launcher driven by a PowerShell encoded command that disables AMSI, sets the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key, sets the UserInitMprLogonScript environment value, registers a scheduled task, and creates a Startup-folder shortcut, hiding the dropped files. It launches the payload detached via wscript.exe and re-checks the C2 host every 2 hours for updates.

analyzed by
Leitwacht
first seen
Aug 29, 2026, 09:06 PM
analyzed
Aug 29, 2026, 09:06 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.