LWA-2026-11763 confirmed malware

developmentstelemetry@1.0.1

Malicious code in developmentstelemetry (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1218.005 · Mshta

Analysis

The postinstall hook runs a JavaScript stub that imports a bundled dependency and calls its downloader. The downloader fetches a remote HTML Application payload (updater.hta) from hxxps://raw[.]githubusercontent[.]com/$Acevatex/Testprogram/main/updater[.]hta, writes it to the system temp directory, and executes it with mshta in a detached, hidden process. This downloads and runs arbitrary remote code on the installer's machine at install time.

analyzed by
Leitwacht
first seen
Aug 30, 2026, 04:55 AM
analyzed
Aug 30, 2026, 04:55 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.