LWA-2026-12260 MAL-2026-16325 ↗ confirmed malware

bulk-add-sdk@1.99.99

Malicious code in bulk-add-sdk (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The install hook runs `node extract.js thd-orangepay`. The script performs host reconnaissance and exfiltrates it to an attacker-controlled domain: it resolves a DNS beacon name of the form `<project_id>.<hostname>.da70vavqatj0sujmhl70w1anmx5ghcr13[.]wallclip[.]me`, fetches the machine's public IP from ifconfig[.]me, then POSTs a JSON payload containing hostname, platform, architecture, current working directory, public IP, and project_id to that wallclip[.]me host over HTTPS (with X-Host, X-Platform, X-Arch, X-CWD, X-IP, X-Project headers). The beacon fires on package install.

analyzed by
Leitwacht
first seen
Sep 18, 2026, 09:55 PM
analyzed
Sep 18, 2026, 09:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.