LWA-2026-11896 confirmed malware
amprem@1.0.1
Malicious code in amprem (npm)
T1539 · Steal Web Session CookieT1567 · Exfiltration Over Web ServiceT1071.001 · Web Protocols
Analysis
A phishing panel for "Alight Motion premium activation". The web frontend (script.js) prompts a victim for their email address and a magic link, then POSTs both to a trycloudflare tunnel endpoint at charge-omissions-bits-prerequisite[.]trycloudflare[.]com (/api/send-link and /api/verify). The magic link is a session credential for the target service, so harvesting it is credential theft. The express server (server.js) only serves the static panel files.
- analyzed by
- Leitwacht
- first seen
- Sep 4, 2026, 03:32 PM
- analyzed
- Sep 4, 2026, 03:33 PM
- weekly installs
- 127
Related advisories
- moidevz@1.0.0
- passport811@1.0.0
- gekko-mev-bot@1.0.0
- system-performance-helper@1.0.1
- react-fontawesome-icons@1.0.5
- @salem_jalal/osc-components@1981.17.7
- shadxino@1.0.7
- parket-helper@0.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.