LWA-2026-4452 confirmed malware

opentracing-shim@55.33.111

Malicious code in opentracing-shim (npm)

T1059.007 · JavaScriptT1082 · System Information Discovery

Analysis

opentracing-shim@55.33.111 is a combosquat of the opentracing namespace using an extremely high version number (55.33.111) on a zero-description package. Its postinstall hook runs a fingerprinting payload that collects hostname, platform, architecture, and timestamp, storing them in a hidden directory (~/.local/share/package-install or AppData\Proofs\package-install) alongside a dropped helper script. This is a staged reconnaissance implant: host-metadata collection on install as a first step that could be followed by exfiltration or a second-stage download.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 09:29 PM
analyzed
Jun 11, 2026, 09:32 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.