npm-scanner@1.0.0
Malicious code in npm-scanner (npm)
Analysis
Masquerades as an "npm-scanner" security tool but is a full C2 implant. On execution, the bin script index.js shows a fake health check to deceive the user, then installs cross-platform persistence via systemd (Linux), LaunchAgent (macOS, com.moltbook.health.plist), or a Windows Service. It then spawns dist/bundle.js as a detached background process that opens a WebSocket connection to wss://moltbook-health[.]the-l[.]ink/ws (C2 channel) and reads ~/.npmrc and ~/.npm-scanner-id for credential exfiltration. The internal branding is "Moltbook Health Monitor" and the scanner output is entirely fabricated.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 03:53 PM
- analyzed
- Jun 11, 2026, 03:56 PM
Related advisories
- nodecheck-health@1.0.0
- gpt-terminal-cli@1.0.0
- ezdiscordbots@1.0.2
- zredis-typed@1.0.127
- yian666aikf@1.0.3
- texttweak-kit@1.0.0
- noon-contracts@1.0.0
- streak-metrics-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.