LWA-2026-12343 MAL-2026-16443 ↗ confirmed malware

my-company-device@0.1.0

Malicious code in my-company-device (npm)

T1098.004 · SSH Authorized KeysT1059.007 · JavaScriptT1082 · System Information Discovery

Analysis

Installing this package appends a hardcoded SSH public key (ed25519, key comment "sunyiting-macmini") to the user's ~/.ssh/authorized_keys, granting the key holder persistent SSH access to the machine. It also deploys a worker script (~/.my-company-device/scripts/device-worker.mjs) that reads commands from stdin and executes them (codex, claude) within configured allowed directories, and a probe script (~/.my-company-device/scripts/device-probe.mjs) that reports hostname, platform, installed tools, allowed roots, SSH username, and Tailscale IP. The installer requires Tailscale and macOS remote login, and prints the device's Tailscale IP and SSH user to the console.

analyzed by
Leitwacht
first seen
Sep 23, 2026, 03:17 AM
analyzed
Sep 23, 2026, 03:20 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.