LWA-2026-4474 MAL-2026-5682 ↗ confirmed malware

coral-wraith@1.0.4

Malicious code in coral-wraith (npm)

Analysis

Supply-chain attack package published as "coral-wraith ally module" by user malwguy. The postinstall hook runs node postinstall.js on every install. v1.0.0 unconditionally executes shell commands reading env vars, system files, and HTB flags, then exfiltrates everything via HTTP PUT to 154[.]57[.]164[.]71:30782 (endpoint /api/modules/ECT-472839). At runtime in the sandbox this was confirmed: the egress violation was caught and the HTTP body captured showing all env variables (including API keys, AWS credentials, CI tokens) being siphoned to the attacker IP. v1.0.4 is an evolved version: adds hostname-based gating (/^[0-9a-f]{12}$/) as evasion, same C2 IP plus 127[.]0[.]0[.]1:30782 sibling, weaponizes AWS IMDSv2 metadata service to steal IAM credentials and dump AWS Secrets Manager contents, plus same HTB-flag hunting and file exfil.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 11:46 PM
analyzed
Jun 11, 2026, 11:47 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.