LWA-2026-11798 MAL-2026-15673 ↗ confirmed malware

fuels-versions@1.0.0

Malicious code in fuels-versions (npm)

T1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's bin script (bin/cli.js, exposed as generate-schema-ethers) runs when invoked via npx and acts as a host-metadata beacon. It collects the local username (via whoami with a fallback to os.userInfo()), the machine hostname, and the OS platform, then POSTs them as JSON to the out-of-band callback endpoint hxxps://oobme[.]kunalsharma0553[.]workers[.]dev/r/7bq6fz3l15r9 (a Cloudflare Workers URL), also sending the package name in the X-Package-Name header and request body. The package description openly states it "POSTs package name and whoami to an OOB callback."

analyzed by
Leitwacht
first seen
Aug 31, 2026, 10:45 AM
analyzed
Aug 31, 2026, 10:45 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.