LWA-2026-12161 MAL-2026-16211 ↗ confirmed malware

swnwall@1.2.10

Malicious code in swnwall (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1059 · Command and Scripting Interpreter

Analysis

swnwall@1.2.10 executes remote code on import. Importing the module (index.js) auto-spawns a detached background `node loader.js` process (persistence via a .pid file). loader.js fetches a JSON payload from hxxps://api[.]npoint[.]io/641d37178a880b1e8b8f, base64-decodes the `code` field, and executes it via the Function constructor with full require/module context — a fully attacker-controlled second stage with no payload shipped in the package. The package also monkeypatches child_process.spawn/execSync to force windowsHide. The declared purpose ("Special layout set module") does not match this behaviour.

analyzed by
Leitwacht
first seen
Sep 16, 2026, 05:35 AM
analyzed
Sep 16, 2026, 05:35 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.