LWA-2026-3393 MAL-2026-5348 ↗ confirmed malware

os-ulid-void@3.0.2

Malicious code in os-ulid-void (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1547.001 · Registry Run Keys / Startup FolderT1053.005 · Scheduled TaskT1543.002 · Systemd ServiceT1552.001 · Credentials In FilesT1056.001 · KeyloggingT1115 · Clipboard DataT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1105 · Ingress Tool TransferT1497 · Virtualization/Sandbox Evasion

Analysis

os-ulid-void@3.0.2 is a combosquat of the legitimate ulid package. Published by ernestmaxwell545 (gmail) impersonating author Alizain Feerasta. Postinstall (dist/utils.mjs) contains: anti-VM CPU-count check, detached background fork, copies 949KB payload.js to persistent directory, and sets up OS persistence across Win (schtasks/reg Run key/VBS), Linux (systemd user service/XDG autostart), and macOS (launchd). Payload.js is a full infostealer: exfiltrates .env/credentials/wallet files, captures keystrokes and clipboard, steals browser profiles and environment variables, and POSTs to XOR-obfuscated C2 at /api/validate/{files,project-env,tdata/upload,ps-history,wallets,keyboard-events}. No [redacted-marker] marker found.

analyzed by
Leitwacht
first seen
Jun 9, 2026, 03:34 AM
analyzed
Jun 9, 2026, 03:35 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.