optional-cpu-features@1.0.3
Malicious code in optional-cpu-features (npm)
Analysis
Package optional-cpu-features@1.0.3 is a trojan disguised as a toolchain CPU-feature probe. install.js runs in both install and postinstall hooks and requires lib/sync.js, which downloads a remote second-stage payload from api[.]aavcareer[.]ink/upd_m (Linux) or api[.]aavcareer[.]ink/upd_w (Windows), saves to /var/tmp/ or %TEMP%, and executes via shell with detached/hidden/ignore flags for stealth. index.js exports `{ supported: true }` as a decoy; README is a cover story. The C2 host is not on any installer allowlist. This is a supply-chain dropper — the description and code are completely misaligned.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 07:07 AM
- analyzed
- Jun 10, 2026, 07:08 AM
Related advisories
- @morpho-blue-liquidation-bot/data-providers@2.0.0
- @morpho-blue-liquidation-bot/pricers@2.0.0
- kepler@1.0.999
- test-flow-entire3@1.0.0
- testingflow2@1.0.0
- @queenanya/baileys@9.7.1
- @cr-invested-ui-components/chart@99.9.1
- utils-style-engine@10.2.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.