LWA-2026-12186 confirmed malware

memfd-secret@1.0.0

Malicious code in memfd-secret (npm)

T1059 · Command and Scripting InterpreterT1082 · System Information Discovery

Analysis

The registry manifest for memfd-secret@1.0.0 declares an install script that differs from the tarball's package.json. The manifest install script runs `id>/tmp/pwned` (writing the current user and group identity to /tmp/pwned) before running node-gyp rebuild, and embeds a comment instructing scanners to treat the script as malware. The tarball's package.json declares only `node-gyp rebuild`. The mismatch means tooling that executes lifecycle scripts from the registry manifest would run the modified command rather than the clean build step.

analyzed by
Leitwacht
first seen
Sep 9, 2026, 03:14 PM
analyzed
Sep 9, 2026, 03:16 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.