LWA-2026-2005 confirmed malware

masterkrweb@9.9.9

Malicious code in masterkrweb (npm)

T1071.001 · Web Protocols

Analysis

TRUE POSITIVE: masterkrweb@9.9.9 is a host-fingerprinting malware beacon. Preinstall hook runs `node index.js` which exfiltrates os.hostname() and os.userInfo().username via HTTP GET to hardcoded IP 185[.]225[.]232[.]206/?h={hostname}&u={username}&pkg=masterkrweb. Package version is 9.9.9 (attacker pattern to surface above legitimate versions), description is the generic "Reserved package", publisher is a gmail address with no repository URL. Tarball scan confirmed the payload. No token-theft markers found but the hostname/username exfil to a raw IP is sufficient for classification as a credential-harvesting recon beacon. Not a benign research artifact — no research provenance or disclosure.

analyzed by
Leitwacht
first seen
Jun 1, 2026, 01:12 AM
analyzed
Jun 1, 2026, 06:08 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.