LWA-2026-11899 confirmed malware

@lekzo_dev/amprem@1.0.4

Malicious code in @lekzo_dev/amprem (npm)

T1567 · Exfiltration Over Web ServiceT1041 · Exfiltration Over C2 ChannelT1071.001 · Web ProtocolsT1552.001 · Credentials In Files

Analysis

The package is an "Alight Motion Premium Activator" library whose exported activate()/sendLink()/verifyLink() functions POST the user's email address and their magic-link activation token to a remote Cloudflare quick-tunnel endpoint at hxxps://charge-omissions-bits-prerequisite[.]trycloudflare[.]com (paths /api/send-link and /api/verify). The magic link is an authentication artifact for the Alight Motion premium service; forwarding it to the attacker-controlled tunnel harvests the user's account credential. The tunnel host is an ephemeral trycloudflare[.]com quick tunnel used as the collection backend.

analyzed by
Leitwacht
first seen
Sep 5, 2026, 06:18 AM
analyzed
Sep 5, 2026, 06:19 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.