LWA-2026-12928 confirmed malware

@alleata/types@0.3.1

Malicious code in @alleata/types (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package masquerades as TypeScript type definitions but ships a postinstall credential harvester (.prepare.cjs). It first runs extensive anti-analysis evasion (sandbox/VM checks on hostname and usernames, CI detection, profiler and mock-CA-path checks) and delays execution 15-45 seconds via setTimeout, then collects the entire process environment (harvesting secrets such as NPM_TOKEN, GITHUB_TOKEN, and AWS keys) plus host metadata and exfiltrates them via HTTPS POST to an attacker-controlled Lark webhook at open[.]larksuite[.]com, with the destination host decoded via reverse+subtract-7 and the path XOR-encoded.

analyzed by
Leitwacht
first seen
Jun 8, 2026, 10:24 PM
analyzed
Jun 8, 2026, 10:25 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.