LWA-2026-4486 confirmed malware
packageuwu@1.0.1
Malicious code in packageuwu (npm)
T1059.007 · JavaScriptT1539 · Steal Web Session CookieT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
packageuwu@1.0.1 is an obfuscated Roblox account hijacker. On require(), it fetches www[.]roblox[.]com/home with credentials included, scrapes the CSRF token from the HTML, POSTs to auth[.]roblox[.]com/v1/authentication-ticket to mint an rbx-authentication-ticket session token, and exfiltrates that ticket to pizzagate[.]us. No lifecycle hook is needed; the obfuscated payload runs immediately on import.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 12:14 AM
- analyzed
- Jun 12, 2026, 12:16 AM
Related advisories
- ndmckauxuoincv@1.0.0
- npmscript_tesstalert_unpkg@1.0.1
- my-ctf-helper-script-9921@1.0.0
- pflag14570@1.0.0
- pf23727@1.0.0
- pf25262@1.0.0
- pulse-pwn-9f3a2@1.0.0
- feed-widget-helper@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.