LWA-2026-12189 confirmed malware
farplotx@1.0.1
Malicious code in farplotx (npm)
T1059 · Command and Scripting InterpreterT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer
Analysis
farplotx ships compiled binaries (bin/cli, bin/cli-linux-amd64, bin/cli-http-linux) instead of the declared JavaScript entry point. The Go binary contains a hardcoded beacon endpoint catcher1[.]corraldev[.]com:8084 and the package README instructs the user to run the binary once to "activate the package in our systems," causing the binary to phone home to that host when executed.
- analyzed by
- Leitwacht
- first seen
- Sep 16, 2026, 05:18 PM
- analyzed
- Sep 16, 2026, 05:19 PM
Related advisories
- ausitool@1.0.1
- strapi-plugin-maylog-meeb@3.6.8
- process-mite@1.1.79
- element-plus-vite-cli@2.9.3
- @asenfotech/unplugin-element-plus@2.9.3
- strapi-plugin-perev-meeb@3.6.8
- strapi-plugin-pysh-meeb@3.6.8
- strapi-plugin-ccip-meeb@3.6.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.