LWA-2026-11896 confirmed malware

amprem@1.0.1

Malicious code in amprem (npm)

T1539 · Steal Web Session CookieT1567 · Exfiltration Over Web ServiceT1071.001 · Web Protocols

Analysis

A phishing panel for "Alight Motion premium activation". The web frontend (script.js) prompts a victim for their email address and a magic link, then POSTs both to a trycloudflare tunnel endpoint at charge-omissions-bits-prerequisite[.]trycloudflare[.]com (/api/send-link and /api/verify). The magic link is a session credential for the target service, so harvesting it is credential theft. The express server (server.js) only serves the static panel files.

analyzed by
Leitwacht
first seen
Sep 4, 2026, 03:32 PM
analyzed
Sep 4, 2026, 03:33 PM
weekly installs
127

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.