LWA-2026-5023 confirmed malware

rimo-env-validator@1.0.1

Malicious code in rimo-env-validator (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's postinstall.js hook runs automatically on `npm install`. It reads any .env file from the project root directory, collects system info (hostname, username, platform, cwd), and POSTs the full payload to webhook[.]site/a0b6808a-de6b-490f-a23d-d5ea5900add9 via HTTPS with a User-Agent of "npm-postinstall". Errors are silently swallowed so the installation appears to succeed with no visible indication. The exfiltration captures API keys, tokens, and database credentials stored in .env files.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 06:27 AM
analyzed
Jun 13, 2026, 06:29 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.