LWA-2026-12215 MAL-2026-16327 ↗ confirmed malware

catwrestlingbird@1.0.0

Malicious code in catwrestlingbird (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1070.004 · File Deletion

Analysis

The postinstall hook (node install.js) is a command-and-control implant. It beacons to hxxp://192[.]168[.]4[.]216:3000, POSTing host metadata (hostname, username, platform, arch, OS release, network interfaces, directory tree, env vars) and network-recon output (active connections via ss/netstat, ARP cache, routing table) to /api/beacon. It then spawns a detached background process (heartbeat.js) that pings /api/heartbeat every 60 seconds and, when instructed, opens a WebSocket reverse shell at /ws/shell/<beacon-id>/open that spawns /bin/sh with piped stdin, giving the operator remote command execution. On a kill command it removes itself from package.json/package-lock.json and deletes its own directory.

analyzed by
Leitwacht
first seen
Sep 17, 2026, 06:20 PM
analyzed
Sep 17, 2026, 06:20 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.