LWA-2026-4486 confirmed malware

packageuwu@1.0.1

Malicious code in packageuwu (npm)

T1059.007 · JavaScriptT1539 · Steal Web Session CookieT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

packageuwu@1.0.1 is an obfuscated Roblox account hijacker. On require(), it fetches www[.]roblox[.]com/home with credentials included, scrapes the CSRF token from the HTML, POSTs to auth[.]roblox[.]com/v1/authentication-ticket to mint an rbx-authentication-ticket session token, and exfiltrates that ticket to pizzagate[.]us. No lifecycle hook is needed; the obfuscated payload runs immediately on import.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 12:14 AM
analyzed
Jun 12, 2026, 12:16 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.