LWA-2026-2338 confirmed malware

@keeneye/uikit@5.0.1

Malicious code in @keeneye/uikit (npm)

T1027 · Obfuscated Files or Information

Analysis

Ships a multi-stage downloader in scripts/postinstall.js (heavily obfuscated). It determines the OS platform via os.platform(), fetches a platform-specific payload from a remote URL over http/https, writes it to ~/.keeneye-uikit, then spawns process.execPath to execute it. The main entry dist/index.js (76 bytes) requires a non-existent ../src/index.js so there is no real logger functionality, and the README contains a fake changelog.

analyzed by
Leitwacht
first seen
Jun 1, 2026, 03:44 PM
analyzed
Jun 1, 2026, 03:52 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.