LWA-2026-1318 confirmed malware

apache-httpclient7@1.0.0

Malicious code in apache-httpclient7 (npm)

Analysis

Functionally identical sibling of apache-httpclient6. The postinstall hook (node src/postinstall.js) spawns a detached background node process running src/main.js, which gathers host recon: OS type/release/version, arch, hostname, uptime, username/homedir/shell, memory, CPU model/count, locale, screen resolution (xrandr/system_profiler/wmic), and a running-process list (ps aux / tasklist) checked for browser/office processes. The JSON payload (flag:myflag_v2) is exfiltrated over a raw TCP socket to 8[.]152[.]163[.]60 on port 8058.

analyzed by
Leitwacht
first seen
May 30, 2026, 06:41 AM
analyzed
May 30, 2026, 06:43 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.