LWA-2026-11764 MAL-2026-15586 ↗ confirmed malware

originaldevelopmentstelemetry@1.2.2

Malicious code in originaldevelopmentstelemetry (npm)

T1105 · Ingress Tool TransferT1218.005 · MshtaT1059.007 · JavaScript

Analysis

The package is a remote-code downloader/loader. Its exported function fetches a remote .hta file from hxxps://raw[.]githubusercontent[.]com/$Acevatex/Testprogram/main/updater[.]hta, writes it to the system temp directory, and executes it via mshta (Windows HTML Application host) as a detached, hidden background process. The downloaded .hta content is attacker-controlled and runs arbitrary script on the host. The package's stated purpose is to download and run this remote client.

analyzed by
Leitwacht
first seen
Aug 30, 2026, 07:02 AM
analyzed
Aug 30, 2026, 07:02 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.