LWA-2026-4025 confirmed malware

mw-filesystem-events-nodream-es6@0.0.32

Malicious code in mw-filesystem-events-nodream-es6 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web Service

Analysis

mw-filesystem-events-nodream-es6 disguises itself as a native filesystem-events library but contains zero real functionality. All three lifecycle hooks (preinstall, install, postinstall) run node index.js, which deploys three parallel exfiltration channels to etbhnvpjylr3xogjwsl2us7g177yvtji[.]oastify[.]com: (1) curl --data '@/etc/passwd' via a subdomain-tagged hostname, (2) an nslookup DNS exfil with base64-encoded package|hostname|user|platform, and (3) an HTTPS POST of a full system fingerprint (hostname, user, platform, release, arch, cwd, pid, node version, home, path, shell) plus /etc/passwd contents. The HTTPS POST with the full JSON payload and multiple DNS queries to the host were observed. The /etc/passwd theft exceeds a host-metadata-only beacon.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 10:12 PM
analyzed
Jun 10, 2026, 10:14 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.