LWA-2026-12188 confirmed malware

ausitool@1.0.1

Malicious code in ausitool (npm)

T1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071 · Application Layer Protocol

Analysis

ausitool@1.0.1 ships a compiled native executable (a Bun-bundled binary) as its CLI. The package README instructs the user to run the bundled binary at least once, stating it "will activate the package in our systems" — a remote-activation / phone-home-on-first-run behaviour. The actual payload is opaque compiled code; the bundled JavaScript entry (src/index.js) is only a decoy dotenv parser reading /home/hatch/test.dat. The declared bin entry points to a bin/cli.js that is not present in the package, so the shipped behaviour is entirely inside the native binary. No network endpoint could be extracted from static strings; the binary's runtime behaviour on execution is the payload.

analyzed by
Leitwacht
first seen
Sep 16, 2026, 05:08 PM
analyzed
Sep 16, 2026, 05:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.