LWA-2026-4934 MAL-2026-5724 ↗ confirmed malware

warp-dependency@1.0.0

Malicious code in warp-dependency (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1204.002 · Malicious FileT1059 · Command and Scripting Interpreter

Analysis

warp-dependency@1.0.0 is a supply-chain attack package. Its postinstall hook runs an obfuscated JavaScript payload that downloads a Windows executable (bss.exe) from a Cloudflare tunnel (recorder-our-betting-chair[.]trycloudflare[.]com/page) using node-fetch, writes it to disk with fs-extra, and executes it via child_process.exec. The package declares sudo-prompt as a dependency (elevation), the publisher uses a throwaway Gmail address, and the description ("Mac UI for Windows Toolkit") is nonsensical. The binary served from the tunnel could perform credential theft, backdoor access, or lateral movement as a second-stage payload.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 11:08 PM
analyzed
Jun 12, 2026, 11:09 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.