LWA-2026-4452 confirmed malware
opentracing-shim@55.33.111
Malicious code in opentracing-shim (npm)
T1059.007 · JavaScriptT1082 · System Information Discovery
Analysis
opentracing-shim@55.33.111 is a combosquat of the opentracing namespace using an extremely high version number (55.33.111) on a zero-description package. Its postinstall hook runs a fingerprinting payload that collects hostname, platform, architecture, and timestamp, storing them in a hidden directory (~/.local/share/package-install or AppData\Proofs\package-install) alongside a dropped helper script. This is a staged reconnaissance implant: host-metadata collection on install as a first step that could be followed by exfiltration or a second-stage download.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 09:29 PM
- analyzed
- Jun 11, 2026, 09:32 PM
Related advisories
- opentelemetry-contrib-scripts@55.33.111
- openclaw-preview@2026.6.1
- worker-build@9.0.1
- index-ulid@3.0.2
- oc-navbar-module-client@9.9.10
- obfus-jsxy@3.2.0
- npm-scanner@1.0.0
- npmjs-doc-builder@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.