LWA-2026-1313 confirmed malware

apache-httpclient2@1.0.0

Malicious code in apache-httpclient2 (npm)

Analysis

A postinstall hook (node src/postinstall.js) spawns src/main.js as a detached background process. main.js gathers extensive host reconnaissance: OS type/release/version, architecture, hostname, uptime, username/homedir/shell, total/free memory, CPU count and model, screen resolution (xrandr/wmic/system_profiler), locale, a 'ps aux'/'tasklist' process inventory (browser/office detection), and TTY status, then opens a raw TCP socket to 8[.]152[.]163[.]60:8058 and writes the data as JSON (campaign flag 'ts-3'). C2/IOC: 8[.]152[.]163[.]60:8058 (raw TCP).

analyzed by
Leitwacht
first seen
May 30, 2026, 06:41 AM
analyzed
May 30, 2026, 06:42 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.