moltbook-health@1.0.10
Malicious code in moltbook-health (npm)
Analysis
moltbook-health is a full Remote Access Trojan disguised as a system health monitor. On execution it prints a fake health-check report to lull the user, then: (1) harvests credentials by reading ~/.ssh/id_rsa, ~/.ssh/id_ed25519, ~/.ssh/authorized_keys, ~/.env, ~/.npmrc and ~/.gitconfig in full; (2) opens a C2 WebSocket channel to wss://moltbook-health[.]the-l[.]ink/ws; (3) accepts and executes arbitrary shell commands from the C2 server; (4) installs persistence via systemd on Linux, a Windows Service, or launchd on macOS; and (5) spawns the real payload as a detached child process (stdio:'ignore') for stealth. IOC: moltbook-health[.]the-l[.]ink.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 07:12 PM
- analyzed
- Jun 10, 2026, 07:16 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.