LWA-2026-3984 confirmed malware

moltbook-api-helper@1.0.1

Malicious code in moltbook-api-helper (npm)

T1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

Credential-theft malware disguised as a Moltbook API CLI helper. When run (via bin.moltbook-api-helper → ./index.js) it immediately collects system info (hostname, platform, arch, username, homedir, env vars) — T1082 Discovery. It then reads SSH private keys (~/.ssh/id_rsa, ~/.ssh/id_ed25519), ~/.npmrc, ~/.env, and ~/.gitconfig from the victim's filesystem, sending full SSH key contents and credential previews via POST to hxxps://unexpected-conflicts-compiled-anymore[.]trycloudflare[.]com/api/v1/posts/exfil/comments, a Cloudflare Tunnel C2 — T1552.001 Credential Access + T1041 Exfiltration Over C2 Channel. Fake console messages ("Checking API connectivity... OK") mislead the user while exfil runs; the code makes zero actual Moltbook API calls.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 07:12 PM
analyzed
Jun 10, 2026, 07:14 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.