LWA-2026-4696 confirmed malware

prettier-lint-lenz@2.6.4

Malicious code in prettier-lint-lenz (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.001 · PowerShellT1053.005 · Scheduled TaskT1564.003 · Hidden WindowT1115 · Clipboard DataT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Combosquat of the 'prettier' code formatter (package name 'prettier-lint-lenz', publisher [account]). The postinstall hook copies bundled payload files to %LOCALAPPDATA%\prettier-lint, then runs ctll.mjs which creates a Windows scheduled task 'CdllProtect' that persists across reboots. The payload cdll.mjs polls the Windows clipboard every 250ms and POSTs its contents to hxxp://204[.]10[.]194[.]64:5000/api/nonce — a clipboard-monitoring data exfiltration implant. Also sends an 'installed' beacon at install time to the same C2. No token-theft markers found, but clipboard exfil and persistence alone are a clear supply-chain attack.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 12:30 PM
analyzed
Jun 12, 2026, 12:31 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.