LWA-2026-3918 confirmed malware

maninos@1.2.0

Malicious code in maninos (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

A decoy TypeScript demo package ('A demo package for Total TypeScript') with a malicious postinstall script. The postinstall reads /proc/self/environ (all process environment variables), greps for 'ingehack', and passes the result as a query parameter via wget to s450r1[.]alwaysdata[.]net/inge/logger.php — targeted environment-variable exfiltration aimed at specific CI/deployment secrets. The actual package code is trivial (an 'add(a,b)=>a+b' function with stubs). ATT&CK: T1552.001 (env var harvest), T1059.007 (postinstall execution), T1071.001 (HTTP exfil to alwaysdata[.]net), T1041 (exfiltration).

analyzed by
Leitwacht
first seen
Jun 10, 2026, 01:14 PM
analyzed
Jun 10, 2026, 01:14 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.