LWA-2026-12189 confirmed malware

farplotx@1.0.1

Malicious code in farplotx (npm)

T1059 · Command and Scripting InterpreterT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

farplotx ships compiled binaries (bin/cli, bin/cli-linux-amd64, bin/cli-http-linux) instead of the declared JavaScript entry point. The Go binary contains a hardcoded beacon endpoint catcher1[.]corraldev[.]com:8084 and the package README instructs the user to run the binary once to "activate the package in our systems," causing the binary to phone home to that host when executed.

analyzed by
Leitwacht
first seen
Sep 16, 2026, 05:18 PM
analyzed
Sep 16, 2026, 05:19 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.