LWA-2026-12169 MAL-2026-16318 ↗ confirmed malware

@asenfotech/unplugin-element-plus@2.9.3

Malicious code in @asenfotech/unplugin-element-plus (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook (postinstall-run.cjs -> tooling-bootstrap.cjs) runs a base64-encoded remote-access agent. On install it registers the host with the C2 server at hxxps://npmjs[.]it[.]com/ (a typosquat of npmjs[.]com) via POST /api/register, sending hostname, username, and OS. It then polls GET /api/task/{agent_id} for commands and executes arbitrary shell commands on the victim machine via cmd.exe /c or /bin/sh -c, uploading command output to /api/result/{agent_id} and file contents to /api/file/{agent_id}/{task_id}. The agent only activates when the consumer project contains specific sentinel files (src/pages/GameAggregator/GameAggrBusinessPage/index.tsx, src/router/RouterProvider.tsx, src/api-gs/dictionaries.ts), indicating a targeted attack. The package's main index.js is a decoy Element Plus resolver.

analyzed by
Leitwacht
first seen
Sep 16, 2026, 08:50 AM
analyzed
Sep 16, 2026, 08:51 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.