LWA-2026-4447 confirmed malware

opentelemetry-contrib-scripts@55.33.111

Malicious code in opentelemetry-contrib-scripts (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1074.001 · Local Data Staging

Analysis

opentelemetry-contrib-scripts@55.33.111 is a version-bump combosquat of OpenTelemetry with no README, description, or repository URL and a nonsensical version (55.33.111). Its postinstall hook writes hostname, platform, and architecture into a stealthy hidden directory (~/.local/share/package-install/ on Linux/macOS, %LOCALAPPDATA%\Proofs\package-install\ on Windows) and drops a dummy helper script with execute permissions. This version performs no network exfiltration, consistent with an incomplete/staged supply-chain payload that fingerprints the host on install.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 09:14 PM
analyzed
Jun 11, 2026, 09:16 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.