LWA-2026-1313 confirmed malware
apache-httpclient2@1.0.0
Malicious code in apache-httpclient2 (npm)
Analysis
A postinstall hook (node src/postinstall.js) spawns src/main.js as a detached background process. main.js gathers extensive host reconnaissance: OS type/release/version, architecture, hostname, uptime, username/homedir/shell, total/free memory, CPU count and model, screen resolution (xrandr/wmic/system_profiler), locale, a 'ps aux'/'tasklist' process inventory (browser/office detection), and TTY status, then opens a raw TCP socket to 8[.]152[.]163[.]60:8058 and writes the data as JSON (campaign flag 'ts-3'). C2/IOC: 8[.]152[.]163[.]60:8058 (raw TCP).
- analyzed by
- Leitwacht
- first seen
- May 30, 2026, 06:41 AM
- analyzed
- May 30, 2026, 06:42 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.