LWA-2026-3985 confirmed malware

moltbook-health@1.0.10

Malicious code in moltbook-health (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1543.003 · Windows ServiceT1543.004 · Launch DaemonT1543.001 · Launch AgentT1036 · MasqueradingT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel

Analysis

moltbook-health is a full Remote Access Trojan disguised as a system health monitor. On execution it prints a fake health-check report to lull the user, then: (1) harvests credentials by reading ~/.ssh/id_rsa, ~/.ssh/id_ed25519, ~/.ssh/authorized_keys, ~/.env, ~/.npmrc and ~/.gitconfig in full; (2) opens a C2 WebSocket channel to wss://moltbook-health[.]the-l[.]ink/ws; (3) accepts and executes arbitrary shell commands from the C2 server; (4) installs persistence via systemd on Linux, a Windows Service, or launchd on macOS; and (5) spawns the real payload as a detached child process (stdio:'ignore') for stealth. IOC: moltbook-health[.]the-l[.]ink.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 07:12 PM
analyzed
Jun 10, 2026, 07:16 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.