LWA-2026-12315 MAL-2026-16385 ↗ confirmed malware

tlxbnhd@0.0.1

Malicious code in tlxbnhd (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1195.002 · Compromise Software Supply Chain

Analysis

The package's preinstall and postinstall hooks (scripts/preinstall.js, scripts/postinstall.js) are obfuscated and, when run, download a remote binary from hxxps://api[.]imghippo[.]com/files/hOG8244hc[.]png (a file-hosting URL disguised with a .png extension), save it as gldriver_pre_core.exe and gldriver_pre_asset.exe inside the package directory, execute both files on the host, then delete them to hide the artifact. Installing this package executes an arbitrary remote binary on the victim's machine.

analyzed by
Leitwacht
first seen
Sep 22, 2026, 03:51 AM
analyzed
Sep 22, 2026, 03:53 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.