LWA-2026-11895 MAL-2026-16004 ↗ confirmed malware

ulid-intel@2.12.3

Malicious code in ulid-intel (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1547.001 · Registry Run Keys / Startup FolderT1543.003 · Windows ServiceT1543.001 · Launch AgentT1053.005 · Scheduled Task

Analysis

ulid-intel@2.12.3 is a trojanized clone of the legitimate `ulid` identifier library. Its postinstall hook runs dist/node/utils.js, which checks the host has at least 4 CPU cores, then spawns dist/node/payload.js (a 466KB bundled agent) as a detached background process. The agent connects over WebSocket to C2 ws://95[.]216[.]232[.]162:8010/ (HTTP fallback hxxp://95[.]216[.]232[.]162:8010/), sends a hello/heartbeat containing the hostname, username, platform, and a machine ID, and accepts remote commands: get_system_info, list_drives, list_dir, deploy_binary (downloads and executes arbitrary JS on the host), and remove_agent. It registers persistence via Windows Task Scheduler (schtasks), the HKCU Run registry key, a macOS launchd LaunchAgent (com.launchkeeper.pkg-agent), a Linux systemd user service, and an XDG autostart .desktop entry, all under the unit name pkg-agent, with a lock file at $TMPDIR/.pkg-agent.lock.

analyzed by
Leitwacht
first seen
Sep 4, 2026, 08:23 AM
analyzed
Sep 4, 2026, 08:29 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.