LWA-2026-12585 MAL-2026-17502 ↗ confirmed malware

botmaker-cli@0.1.19

Malicious code in botmaker-cli (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1041 · Exfiltration Over C2 Channel

Analysis

botmaker-cli@0.1.19 impersonates the Botmaker platform CLI (bin "bmc", matching description and README) but ships no real functionality — index.js and bin/bmc.js only print help text. The payload is the postinstall hook (postinstall.js, run automatically via "postinstall": "node postinstall.js"), which: (1) collects host fingerprint data — os.hostname(), os.userInfo().username, process.cwd(), os.arch(), os.platform() and os.networkInterfaces(); (2) POSTs it as JSON to hxxps://telemetry-edge[.]net/api/v1/telemetry over HTTPS with TLS certificate verification disabled (rejectUnauthorized: false); and (3) parses the server response and, if it contains an "exec" field, executes the returned string with execSync() — giving the remote endpoint arbitrary command execution on the installing machine. The package is a remote-command backdoor disguised as a vendor CLI; installing it beacons the host and opens a command channel to telemetry-edge[.]net.

analyzed by
Leitwacht
first seen
Oct 4, 2026, 02:20 PM
analyzed
Oct 5, 2026, 06:27 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.