LWA-2026-2315 MAL-2026-5558 ↗ confirmed malware

sensivity@2.5.7

Malicious code in sensivity (npm)

T1027 · Obfuscated Files or Information

Analysis

sensivity@2.5.7 is a trojan disguised as a "Mobile Control Panel". launcher.js masquerades its process as "Runtime Broker", installs HKCU\Run persistence via PowerShell under the fake name "OneDriveUpdate", deploys OneDrive.Standalone.Updater.vbs (named to mimic Microsoft) to silently launch the payload, and monitors Chrome for YouTube tabs to display a QR code (a YouTube session-hijack / cookie-theft pattern). The core logic is a 76KB self-defending obfuscated server.obf.js (~4900 _0x identifiers) loaded via eval(fs.readFileSync(...)). Persistence, masquerading, anti-analysis obfuscation and YouTube-targeted QR phishing are definitive malware indicators.

analyzed by
Leitwacht
first seen
Jun 1, 2026, 02:57 PM
analyzed
Jun 1, 2026, 03:06 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.