LWA-2026-2338 confirmed malware
@keeneye/uikit@5.0.1
Malicious code in @keeneye/uikit (npm)
T1027 · Obfuscated Files or Information
Analysis
Ships a multi-stage downloader in scripts/postinstall.js (heavily obfuscated). It determines the OS platform via os.platform(), fetches a platform-specific payload from a remote URL over http/https, writes it to ~/.keeneye-uikit, then spawns process.execPath to execute it. The main entry dist/index.js (76 bytes) requires a non-existent ../src/index.js so there is no real logger functionality, and the README contains a fake changelog.
- analyzed by
- Leitwacht
- first seen
- Jun 1, 2026, 03:44 PM
- analyzed
- Jun 1, 2026, 03:52 PM
Related advisories
- @keeneye/toolkit@5.0.1
- @gbrlxvi/ts-form-utils@2.1.1
- sensivity@2.5.7
- sensivity@2.5.5
- sensivity@2.5.3
- sensivity@2.5.2
- sensivity@2.5.0
- argoncrypt@1.2.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.