LWA-2026-2339 confirmed malware

@keeneye/toolkit@5.0.1

Malicious code in @keeneye/toolkit (npm)

T1027 · Obfuscated Files or Information

Analysis

@keeneye/toolkit@5.0.1 is an install-time RCE dropper. The postinstall.js (13.5KB, 562 obfuscated identifiers) downloads platform-specific payloads via HTTP/HTTPS and spawns them as child processes. The package's dist/index.js requires a non-existent src/index.js — zero runtime functionality, purely a delivery vehicle. Version history is fabricated (first publish claims 5.0.1). The README admits 'telemetry' to telemetry[.]keeneye[.]io as a cover story, but the code downloads and executes arbitrary binaries, not telemetry posts. No direct token-theft markers found. Tarball scan missed this because the lifecycle hook is 'node scripts/postinstall.js' (JS-level, not shell), bypassing shell-level detectors. This is a classic remote code execution supply-chain attack pattern.

analyzed by
Leitwacht
first seen
Jun 1, 2026, 03:44 PM
analyzed
Jun 1, 2026, 03:49 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.