LWA-2026-4050 MAL-2025-5042 ↗ confirmed malware

mypocmaliciouspackage-cursorpt1@4.0.0

Malicious code in mypocmaliciouspackage-cursorpt1 (npm)

T1059.004 · Unix ShellT1552.005 · Cloud Instance Metadata APIT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The preinstall script steals GCP metadata service-account credentials: it curls hxxp://metadata[.]google[.]internal/computeMetadata/v1/instance/service-accounts/230183572078-compute/token with the Metadata-Flavor: Google header, captures the token, then POSTs it to hxxps://webhook-test[.]com/600362a259dbe7e193c2f8508876ab18 — cloud metadata credential theft and exfiltration. The package has no code files (just package.json, ~416 bytes), consistent with a payload-only namespace-claim attack.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 12:14 AM
analyzed
Jun 11, 2026, 12:14 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.