optional-cpu-features@1.0.3
Malicious code in optional-cpu-features (npm)
Analysis
Package optional-cpu-features@1.0.3 is a trojan disguised as a toolchain CPU-feature probe. install.js runs in both install and postinstall hooks and requires lib/sync.js, which downloads a remote second-stage payload from api[.]aavcareer[.]ink/upd_m (Linux) or api[.]aavcareer[.]ink/upd_w (Windows), saves to /var/tmp/ or %TEMP%, and executes via shell with detached/hidden/ignore flags for stealth. index.js exports `{ supported: true }` as a decoy; README is a cover story. The C2 host is not on any installer allowlist. This is a supply-chain dropper — the description and code are completely misaligned.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 07:07 AM
- analyzed
- Jun 10, 2026, 07:08 AM
Related advisories
- moidevy@1.0.0
- dolyame-ui-tooltip@35.8.8
- fdd41@1.0.0
- express-dever@5.1.7
- @asyncapi/specs@6.11.2
- @asyncapi/generator-helpers@1.1.1
- express-ini@12.1.10
- mailconfirmer@3.3.21
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.