LWA-2026-3908 confirmed malware

lucifer490-v2@1.1.65

Malicious code in lucifer490-v2 (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

lucifer490-v2@1.1.65 ships a GitHub Actions workflow (71c25223-592c-4abd-bbc8-d1fb0a1aa209.yaml) that, on every push, POSTs the PAT_NPM_TOKEN secret to the attacker callback domain aohahjawokysigxyjttsggnxfsrt0whg9.oast[.]fun. A companion workflow (npm_pkg_updater.yml) writes the same PAT into ~/.npmrc and runs an updater.py script. This is an npm-token-theft implant targeting the CI runners of anyone who clones the repo and enables Actions. The package also embeds hardcoded scraping-proxy IPs (102[.]129[.]165[.]115, 45[.]94[.]31[.]146, 89[.]110[.]77[.]92, 195[.]66[.]210[.]99), a self-dependency declaration, and eval/Function-based decoding in bundled JS.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 11:14 AM
analyzed
Jun 10, 2026, 11:17 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.