LWA-2026-4006 confirmed malware

mongodb-example@55.33.111

Malicious code in mongodb-example (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1074.001 · Local Data Staging

Analysis

Install-environment probe / payload stager: mongodb-example@55.33.111. A postinstall hook calls does.js, which (1) creates a stealth directory at ~/.local/share/package-install or AppData\Proofs\package-install; (2) writes a host fingerprint beacon (hostname, platform, arch, timestamp) to install_log.txt; and (3) drops and chmods a helper.sh/helper.exe placeholder executable. The declared postinstall path (scripts/does.js) mismatches the actual file (does.js), a packaging error, but the intent to probe the install environment and stage a payload on disk is unambiguous.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 07:42 PM
analyzed
Jun 10, 2026, 07:44 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.