LWA-2026-4327 MAL-2026-2275 ↗ confirmed malware

npmamzs@1.1.1

Malicious code in npmamzs (npm)

Analysis

npmamzs@1.1.1 is a supply-chain attack package with no description, README, or legitimate functionality. Its postinstall hook runs index.js, which fetches a remote shell script from an ngrok tunnel at hxxps://reunionistic-keagan-unfestively[.]ngrok-free[.]dev/rev.sh and executes it via bash in a detached child process. Its sole purpose is downloading and running a second-stage payload from attacker-controlled infrastructure.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 03:08 PM
analyzed
Jun 11, 2026, 03:30 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.