LWA-2026-1318 confirmed malware
apache-httpclient7@1.0.0
Malicious code in apache-httpclient7 (npm)
Analysis
Functionally identical sibling of apache-httpclient6. The postinstall hook (node src/postinstall.js) spawns a detached background node process running src/main.js, which gathers host recon: OS type/release/version, arch, hostname, uptime, username/homedir/shell, memory, CPU model/count, locale, screen resolution (xrandr/system_profiler/wmic), and a running-process list (ps aux / tasklist) checked for browser/office processes. The JSON payload (flag:myflag_v2) is exfiltrated over a raw TCP socket to 8[.]152[.]163[.]60 on port 8058.
- analyzed by
- Leitwacht
- first seen
- May 30, 2026, 06:41 AM
- analyzed
- May 30, 2026, 06:43 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.