LWA-2026-4625 confirmed malware

pocbitbarrontest@1.0.0

Malicious code in pocbitbarrontest (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.006 · PythonT1543 · Create or Modify System ProcessT1555.003 · Credentials from Web BrowsersT1555.001 · KeychainT1552.001 · Credentials In FilesT1539 · Steal Web Session CookieT1555.005 · Password ManagersT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1102.002 · DiscordT1005 · Data from Local SystemT1041 · Exfiltration Over C2 Channel

Analysis

A credential-stealing implant with persistent Discord C2. The postinstall hook (node scripts/collect.js) performs comprehensive credential harvesting: it reads browser saved passwords via a Python helper (Chrome/Brave/Edge AES-GCM + DPAPI decryption), steals Discord tokens from LevelDB, scrapes Telegram sessions, reads ~/.aws/credentials, GCloud/Azure configs, the macOS Keychain, SSH private keys, and .env files containing API keys (Stripe, AWS, GitHub). It fingerprints the host via hxxps://api.ipify[.]org and exfiltrates everything to a Discord webhook as an embed with file attachments. It then spawns agent.js as a detached background process — a full C2 implant that connects to Discord's Gateway WebSocket, listens for commands in a C2 channel, and supports remote screenshot capture, file exfiltration from Documents/Desktop, and downloading and executing arbitrary payloads.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 09:57 AM
analyzed
Jun 12, 2026, 09:58 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.