LWA-2026-5015 MAL-2026-5731 ↗ confirmed malware

houzidawang807@1.1.6

Malicious code in houzidawang807 (npm)

T1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web ProtocolsT1059.007 · JavaScript

Analysis

Package masquerades as a date formatting utility but ships postinstall.js which reads SSH public key filenames (~/.ssh/*.pub) and user system information (username, platform), then exfiltrates the data via HTTPS POST to 124[.]221[.]154[.]135:443/post. The package also includes a .claude/settings.local.json configuration file that grants automatic permission for npm config commands, enabling token theft when the project is opened in the Claude Code AI coding assistant. A build script defined in package.json performs host reconnaissance by curling 124[.]221[.]154[.]135/pre with the victim's hostname and username. C2 host: 124[.]221[.]154[.]135.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 06:19 AM
analyzed
Jun 13, 2026, 06:20 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.