LWA-2026-4271 confirmed malware

node-gyp-runtime@1.0.0

Malicious code in node-gyp-runtime (npm)

T1036.005 · Match Legitimate Resource Name or LocationT1059.007 · JavaScriptT1547.001 · Registry Run Keys / Startup FolderT1547.009 · Shortcut ModificationT1547.011 · Linux AutostartT1082 · System Information DiscoveryT1005 · Data from Local SystemT1217 · Browser Information DiscoveryT1123 · Audio CaptureT1113 · Screen CaptureT1056 · Input CaptureT1071.001 · Web Protocols

Analysis

node-gyp-runtime@1.0.0 is a full-featured remote-access trojan combosquatting node-gyp. The postinstall.js copies all source to a hidden directory (~/.node-gyp-cache / %APPDATA%\node-gyp-cache), registers cross-platform persistence (Windows HKCU\Run via a wscript.exe VBS launcher, macOS LaunchAgent, Linux autostart desktop entry), and spawns a detached background agent. The agent connects to a configurable Socket[.]IO C2, registers with machine ID and system info, and supports screenshot streaming (screenshot-desktop + sharp), microphone/system audio capture (ffmpeg), browser-history theft from Chrome/Edge/Firefox (better-sqlite3), filesystem browsing and file reads, and full remote mouse/keyboard control (robotjs).

analyzed by
Leitwacht
first seen
Jun 11, 2026, 12:07 PM
analyzed
Jun 11, 2026, 12:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.