LWA-2026-2269 MAL-2026-5558 ↗ confirmed malware

sensivity@2.5.2

Malicious code in sensivity (npm)

T1140 · Deobfuscate/Decode Files or InformationT1027 · Obfuscated Files or Information

Analysis

sensivity@2.5.2 is a credential-harvesting/scam toolkit that persists on the victim machine. launcher.js loads an 85KB obfuscated payload (server.obf.js) via eval(fs.readFileSync('server.obf.js','utf8')), masquerades its process as 'Runtime Broker', installs registry persistence at HKCU\Run under 'OneDriveUpdate', and deploys OneDrive.Standalone.Updater.vbs to silently relaunch via wscript. It detects Chrome YouTube windows to trigger a QR-code display (a YouTube-scam credential-harvesting pattern), ships a 6.8MB native sens.node binary, and embeds a license-auth endpoint with a public key.

analyzed by
Leitwacht
first seen
Jun 1, 2026, 02:14 PM
analyzed
Jun 1, 2026, 02:30 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.