LWA-2026-12296 confirmed malware
lynxog@4.0.0
Malicious code in lynxog (npm)
T1195.002 · Compromise Software Supply ChainT1027 · Obfuscated Files or InformationT1059.007 · JavaScript
Analysis
The package's main entry point (main.js) is a heavily obfuscated JavaScript payload, alongside a second 1.1MB obfuscated file (Levvi.js). It declares a dependency on the WhatsApp library @whiskeysockets/baileys but aliases it to npm:levvleys, so installing the package pulls in an attacker-controlled substitute for the real library that the bundled bot code imports. A functional WhatsApp bot module (lynx/index.mjs) is shipped alongside the obfuscated payloads.
- analyzed by
- Leitwacht
- first seen
- Sep 21, 2026, 08:53 AM
- analyzed
- Sep 21, 2026, 08:55 AM
Related advisories
- ndmcjcxiebysfdb@1.0.0
- testmgkregme@1.0.1
- @shared-web/assets@9.9.10
- tailwind-form-styles@0.5.1
- hardhat-devkit@2.3.6
- tailwindcss-form@0.5.1
- chai-as-crack@7.0.5
- @biz44/id44-client@1.1.44
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.