LWA-2026-12191 confirmed malware
farplotzy@0.1.0
Malicious code in farplotzy (npm)
T1059 · Command and Scripting InterpreterT1071 · Application Layer ProtocolT1105 · Ingress Tool Transfer
Analysis
The package ships opaque native executables (a Go binary and a Bun-compiled binary) alongside a thin React wrapper. The Linux Go binary contains a hardcoded network endpoint catcher1[.]corraldev[.]com:8084. The package's declared bin entry points to bin/cli.js, which is not present in the tarball; the actual executables are native binaries whose behaviour is not visible in the source. The React wrapper posts plot data to api[.]farplotzy[.]dev/v1/render with a Bearer token.
- analyzed by
- Leitwacht
- first seen
- Sep 16, 2026, 05:40 PM
- analyzed
- Sep 16, 2026, 05:42 PM
Related advisories
- ausitool@1.0.1
- strapi-plugin-feedmeeb@3.6.8
- strapi-plugin-maylog-meeb@3.6.8
- strapi-plugin-perev-meeb@3.6.8
- strapi-plugin-rsh-meeb322k@3.6.8
- strapi-plugin-revsh-meeb322k@3.6.8
- strapi-plugin-revs-meeb322k@3.6.8
- strapi-plugin-rs-meeb322k@3.6.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.