LWA-2026-4401 MAL-2026-5827 ↗ confirmed malware

index-ulid@3.0.2

Malicious code in index-ulid (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1053.005 · Scheduled TaskT1547.001 · Registry Run Keys / Startup FolderT1543.002 · Systemd ServiceT1555.003 · Credentials from Web BrowsersT1552.001 · Credentials In FilesT1552.004 · Private KeysT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1041 · Exfiltration Over C2 ChannelT1480 · Execution Guardrails

Analysis

index-ulid combosquats the popular ulid npm package. The postinstall hook spawns a detached, hidden child process that copies a 950KB implant (payload.js) to a persistent directory named MicrosoftSystem64 and installs cross-platform persistence (Windows scheduled task/registry Run key, macOS launchd, Linux systemd user service / XDG autostart). The implant XOR-obfuscates its WebSocket and HTTP C2 URLs, checks CPU count as anti-sandbox, and steals credentials from Chrome/Edge/Brave/Firefox browsers, FileZilla, Telegram Desktop, SSH keys, and OneDrive. It dumps all process.env variables (targeting NPM_TOKEN, GITHUB_TOKEN, AWS credentials) and exfiltrates them to the C2 server. The package claims the original ulid author but is published by a different user (probull100).

analyzed by
Leitwacht
first seen
Jun 11, 2026, 07:07 PM
analyzed
Jun 11, 2026, 07:08 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.