LWA-2026-4234 confirmed malware

node-env-resolve@1.0.0

Malicious code in node-env-resolve (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1547.001 · Registry Run Keys / Startup FolderT1547.009 · Shortcut ModificationT1564.003 · Hidden WindowT1082 · System Information DiscoveryT1113 · Screen CaptureT1123 · Audio CaptureT1005 · Data from Local SystemT1217 · Browser Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

node-env-resolve@1.0.0 is a full-featured remote-access trojan published under a benign "environment resolver" description. The postinstall.js copies the package source to a hidden directory (~/.node-gyp-cache or AppData\Roaming\node-gyp-cache), installs dependencies, registers OS-level persistence (Windows HKCU\Run + VBS launcher, macOS LaunchAgent, Linux ~/.config/autostart), and spawns src/index.js as a detached hidden process. The agent connects over a socket[.]io WebSocket to a configurable C2 (default localhost:8471, overridable via SERVER_URL) and supports remote screen capture, microphone audio capture, filesystem browsing and file reads (including .env), browser-history theft from Chrome/Edge/Firefox SQLite stores, remote mouse/keyboard injection (robotjs), and host fingerprinting. Its dependency set (robotjs, screenshot-desktop, socket[.]io-client, node-machine-id, sharp, better-sqlite3) is consistent with a surveillance agent.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 11:45 AM
analyzed
Jun 11, 2026, 11:46 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.