LWA-2026-11763 confirmed malware
developmentstelemetry@1.0.1
Malicious code in developmentstelemetry (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1218.005 · Mshta
Analysis
The postinstall hook runs a JavaScript stub that imports a bundled dependency and calls its downloader. The downloader fetches a remote HTML Application payload (updater.hta) from hxxps://raw[.]githubusercontent[.]com/$Acevatex/Testprogram/main/updater[.]hta, writes it to the system temp directory, and executes it with mshta in a detached, hidden process. This downloads and runs arbitrary remote code on the installer's machine at install time.
- analyzed by
- Leitwacht
- first seen
- Aug 30, 2026, 04:55 AM
- analyzed
- Aug 30, 2026, 04:55 AM
Related advisories
- gptmini@4.0.2
- openllmapi@4.0.2
- easyllmai@3.0.1
- originaldevelopmentstelemetry@1.2.2
- node-request-utils@1.0.0
- mfaatest@1.0.0
- mfafix@1.0.0
- cbc97b7a@1.1787999998.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.