LWA-2026-12271 MAL-2026-16343 ↗ confirmed malware

siriusbeyond@1.0.0

Malicious code in siriusbeyond (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1048 · Exfiltration Over Alternative Protocol

Analysis

The package runs a callback script in both its preinstall and postinstall hooks. The script fingerprints the host (hostname, username, platform, working directory, home directory, network IP addresses, process UID/GID/PID), detects the CI/CD environment and cloud provider, enumerates the names of sensitive environment variables (matching token/secret/key/password patterns), and checks for the presence of credential files (.env, .npmrc, .git/config, .docker/config.json). It POSTs the collected data to the Telegram Bot API (api[.]telegram[.]org) using a hardcoded bot token and chat ID, and attempts DNS-based exfiltration to dc-callback[.]example[.]com as a backup channel.

analyzed by
Leitwacht
first seen
Sep 20, 2026, 01:11 AM
analyzed
Sep 20, 2026, 01:12 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.