LWA-2026-4519 confirmed malware
parkhaima@1.0.0
Malicious code in parkhaima (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
The postinstall hook (node index.js) executes an IIFE that HTTP GETs a JavaScript payload from internal-mirror[.]southindia[.]cloudapp[.]azure[.]com:5000/1week_utils-helper.js, then compiles and runs it via Module._compile. This is a remote code fetch-and-execute (second-stage downloader) against a non-standard host on port 5000 — not an allowlisted installer. No legitimate purpose for fetching arbitrary code at install time. The small 552-byte stub is consistent with a minimal downloader that pulls the real payload from the C2 server.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 01:15 AM
- analyzed
- Jun 12, 2026, 01:16 AM
Related advisories
- paper-password-input@45.0.0
- pampipes@1.1.9
- chai-web3-testkit@1.0.1
- req-parmas-valid@1.0.2
- mddriver@1.8.6
- vite-config-react@1.3.1
- openclaw-preview@2026.6.1
- one-intuit-help-system-utils@45.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.