LWA-2026-4559 confirmed malware

period-newline@0.1.0

Malicious code in period-newline (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1070.004 · File DeletionT1552.001 · Credentials In FilesT1552.004 · Private KeysT1555.003 · Credentials from Web BrowsersT1082 · System Information DiscoveryT1005 · Data from Local SystemT1071 · Application Layer ProtocolT1573.001 · Symmetric CryptographyT1041 · Exfiltration Over C2 Channel

Analysis

period-newline@0.1.0 poses as a tiny text formatter (inserts newlines after periods) but ships a malicious postinstall hook (dist/index5_test.js). On install, the hook: (1) self-deletes and overwrites package.json with a dummy — evasion; (2) AES-256-CTR decrypts embedded payload strings revealing a TCP C2 endpoint, credential-target paths, and an AES-GCM encryption key; (3) reads ~/.ssh/id_rsa, ~/.aws/credentials, ~/.docker/config.json, ~/.npmrc, ~/.netrc, Chrome Login Data, .env files, and git history; (4) collects hostname, username, and external IP from api[.]ipify[.]org; (5) encrypts all stolen data with AES-GCM and exfiltrates over TCP to the C2. Publisher ([account] The legitimate-looking README and CLI are a decoy for a full credential-theft implant.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 06:14 AM
analyzed
Jun 12, 2026, 06:15 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.