LWA-2026-5023 confirmed malware
rimo-env-validator@1.0.1
Malicious code in rimo-env-validator (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The package's postinstall.js hook runs automatically on `npm install`. It reads any .env file from the project root directory, collects system info (hostname, username, platform, cwd), and POSTs the full payload to webhook[.]site/a0b6808a-de6b-490f-a23d-d5ea5900add9 via HTTPS with a User-Agent of "npm-postinstall". Errors are silently swallowed so the installation appears to succeed with no visible indication. The exfiltration captures API keys, tokens, and database credentials stored in .env files.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 06:27 AM
- analyzed
- Jun 13, 2026, 06:29 AM
Related advisories
- houzidawang807@1.1.6
- renovate-config-doctolib@9.9.16
- redeem-onchain-sdk@1.0.1
- react-svg-chunk@1.1.0
- pt-logger-telemetry-eax0x1@1.0.0
- pretty-pino-logger@2.0.2
- prettlog@1.0.10
- ttspc-server-sample@9.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.