LWA-2026-2409 MAL-2026-5558 ↗ confirmed malware

sensivity@2.5.23

Malicious code in sensivity (npm)

T1027 · Obfuscated Files or Information

Analysis

Malware cluster: sensivity@2.5.22–2.5.25 (26 versions published in hours by throwaway Gmail account). Contains: (1) launcher.js — spawns detached supervisor/worker processes (hide as "Runtime Broker"), patches Module._load to intercept .node loading, masks log output; (2) OneDrive.Standalone.Updater.vbs — fake OneDrive VBS that silently runs the launcher; (3) ensureAutostart() sets HKCU\Windows\CurrentVersion\Run "OneDriveUpdate" reg key for persistence; (4) server.obf.js — heavily obfuscated (5227+ _0x identifiers) eval'd by launcher; (5) sens.node — 6.8MB binary payload (likely native addon). All 12 findings across 4 versions share identical attack shape.

analyzed by
Leitwacht
first seen
Jun 1, 2026, 06:02 PM
analyzed
Jun 1, 2026, 06:21 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.