originaldevelopmentstelemetry@1.2.2
Malicious code in originaldevelopmentstelemetry (npm)
T1105 · Ingress Tool TransferT1218.005 · MshtaT1059.007 · JavaScript
Analysis
The package is a remote-code downloader/loader. Its exported function fetches a remote .hta file from hxxps://raw[.]githubusercontent[.]com/$Acevatex/Testprogram/main/updater[.]hta, writes it to the system temp directory, and executes it via mshta (Windows HTML Application host) as a detached, hidden background process. The downloaded .hta content is attacker-controlled and runs arbitrary script on the host. The package's stated purpose is to download and run this remote client.
- analyzed by
- Leitwacht
- first seen
- Aug 30, 2026, 07:02 AM
- analyzed
- Aug 30, 2026, 07:02 AM
Related advisories
- developmentstelemetry@1.0.1
- gptmini@4.0.2
- openllmapi@4.0.2
- easyllmai@3.0.1
- node-request-utils@1.0.0
- mfaatest@1.0.0
- mfafix@1.0.0
- cbc97b7a@1.1787999998.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.