LWA-2026-4519 confirmed malware

parkhaima@1.0.0

Malicious code in parkhaima (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

The postinstall hook (node index.js) executes an IIFE that HTTP GETs a JavaScript payload from internal-mirror[.]southindia[.]cloudapp[.]azure[.]com:5000/1week_utils-helper.js, then compiles and runs it via Module._compile. This is a remote code fetch-and-execute (second-stage downloader) against a non-standard host on port 5000 — not an allowlisted installer. No legitimate purpose for fetching arbitrary code at install time. The small 552-byte stub is consistent with a minimal downloader that pulls the real payload from the C2 server.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 01:15 AM
analyzed
Jun 12, 2026, 01:16 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.