LWA-2026-4486 confirmed malware
packageuwu@1.0.1
Malicious code in packageuwu (npm)
T1059.007 · JavaScriptT1539 · Steal Web Session CookieT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
packageuwu@1.0.1 is an obfuscated Roblox account hijacker. On require(), it fetches www[.]roblox[.]com/home with credentials included, scrapes the CSRF token from the HTML, POSTs to auth[.]roblox[.]com/v1/authentication-ticket to mint an rbx-authentication-ticket session token, and exfiltrates that ticket to pizzagate[.]us. No lifecycle hook is needed; the obfuscated payload runs immediately on import.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 12:14 AM
- analyzed
- Jun 12, 2026, 12:16 AM
Related advisories
- gekko-mev-bot@1.0.0
- system-performance-helper@1.0.1
- react-fontawesome-icons@1.0.5
- @salem_jalal/osc-components@1981.17.7
- shadxino@1.0.7
- parket-helper@0.0.1
- textdecode@1.2.7
- pocbitbarrontest@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.