LWA-2026-3828 MAL-2026-5642 ↗ confirmed malware

optional-cpu-features@1.0.3

Malicious code in optional-cpu-features (npm)

T1059.007 · JavaScriptT1059.004 · Unix ShellT1059.003 · Windows Command ShellT1105 · Ingress Tool TransferT1564.003 · Hidden WindowT1195 · Supply Chain Compromise

Analysis

Package optional-cpu-features@1.0.3 is a trojan disguised as a toolchain CPU-feature probe. install.js runs in both install and postinstall hooks and requires lib/sync.js, which downloads a remote second-stage payload from api[.]aavcareer[.]ink/upd_m (Linux) or api[.]aavcareer[.]ink/upd_w (Windows), saves to /var/tmp/ or %TEMP%, and executes via shell with detached/hidden/ignore flags for stealth. index.js exports `{ supported: true }` as a decoy; README is a cover story. The C2 host is not on any installer allowlist. This is a supply-chain dropper — the description and code are completely misaligned.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 07:07 AM
analyzed
Jun 10, 2026, 07:08 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.