LWA-2026-12645 confirmed malware

@praveenvjpm/color-utils-7210@1.0.0

Malicious code in @praveenvjpm/color-utils-7210 (npm)

T1059.007 · JavaScriptT1036 · MasqueradingT1082 · System Information DiscoveryT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

@praveenvjpm/color-utils-7210@1.0.0 contains no library code — only a package.json and an install.js — and declares a preinstall hook ("node install.js") that executes automatically on npm install. The hook performs host reconnaissance (os.hostname(), process.cwd(), USER/USERNAME), reads the contents of /flag, /flag.txt, /app/flag, /home/node/flag and /tmp/flag, and exfiltrates the combined result over HTTP PUT to hxxp://154[.]57[.]164[.]66:39270/api/modules/<id> for four hardcoded module ids (ECT-987654, ECT-472839, ECT-654321, ECT-839201). The stolen data is wrapped in a YAML "ecto_module" manifest with version "pwned" and power_level "CURSED". Network errors are silently swallowed. The package's stated purpose (color conversion utilities) does not match its contents, and the install hook is its only behaviour.

analyzed by
Leitwacht
first seen
Oct 7, 2026, 01:16 PM
analyzed
Oct 7, 2026, 01:16 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.