LWA-2026-4618 MAL-2026-5720 ↗ confirmed malware

ect-839201@100.0.1

Malicious code in ect-839201 (npm)

T1059.004 · Unix ShellT1005 · Data from Local SystemT1041 · Exfiltration Over C2 Channel

Analysis

The preinstall hook in this package reads /flag.txt from the host and exfiltrates it: it first tries to copy it to web-accessible static directories (/app/public/static/flag.txt, /app/static/flag.txt), and if both fail it uses curl to POST the file content to an attacker-controlled IP (10[.]107[.]121[.]85:8000/flag). The package is version 100.0. This is a flag-stealing payload targeting environments where a /flag.txt exists.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 09:03 AM
analyzed
Jun 12, 2026, 09:05 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.