LWA-2026-4013 MAL-2026-5538 ↗ confirmed malware

hex-type@3.0.2

Malicious code in hex-type (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1053.005 · Scheduled TaskT1547.001 · Registry Run Keys / Startup FolderT1543.002 · Systemd ServiceT1547.009 · Shortcut ModificationT1564.003 · Hidden WindowT1055 · Process InjectionT1497 · Virtualization/Sandbox EvasionT1552.001 · Credentials In FilesT1552.004 · Private KeysT1555 · Credentials from Password StoresT1115 · Clipboard DataT1113 · Screen CaptureT1056.001 · KeyloggingT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1573 · Encrypted ChannelT1567.002 · Exfiltration to Cloud StorageT1041 · Exfiltration Over C2 Channel

Analysis

hex-type@3.0.2 is a combosquat C2 implant masquerading as the ULID library (README copied from github[.]com/ulid/javascript, published by new user hexalpha16). Postinstall (dist/utils.js) spawns a detached background process, copies 949KB payload.js to persistent dir, and sets up platform persistence: Windows (schtasks + registry Run key + VBS), Linux (systemd user service + XDG autostart), macOS (detached spawn). The payload runs as --agent, sets process.title="MicrosoftSystem64", and implements a full C2 agent: WebSocket + HTTP POST to configurable SERVER_URL, with remote commands for credential file scanning (wallet keys for sol/eth/exodus/trustwallet, .env, .git-credentials, .netrc, .pgpass, SSH keys), Telegram data theft, clipboard monitoring, keylogging, and screenshot capture — all exfiltrated to HuggingFace via hfToken/hfUsername. Anti-VM check requires ≥5 CPUs. This is supply-chain malware.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 08:15 PM
analyzed
Jun 10, 2026, 08:17 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.