LWA-2026-12186 confirmed malware
memfd-secret@1.0.0
Malicious code in memfd-secret (npm)
T1059 · Command and Scripting InterpreterT1082 · System Information Discovery
Analysis
The registry manifest for memfd-secret@1.0.0 declares an install script that differs from the tarball's package.json. The manifest install script runs `id>/tmp/pwned` (writing the current user and group identity to /tmp/pwned) before running node-gyp rebuild, and embeds a comment instructing scanners to treat the script as malware. The tarball's package.json declares only `node-gyp rebuild`. The mismatch means tooling that executes lifecycle scripts from the registry manifest would run the modified command rather than the clean build step.
- analyzed by
- Leitwacht
- first seen
- Sep 9, 2026, 03:14 PM
- analyzed
- Sep 9, 2026, 03:16 PM
Related advisories
- open-item-validator@1.0.2
- date-fns-formatter@1.3.8
- multicore-kit@1.1.5
- jwt-logger@2.1.9
- ulid-intel@2.12.3
- 2nestjs@0.0.1
- 1nestjs@0.0.1
- 0nestjs@0.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.