LWA-2026-5068 confirmed malware

saps_secplayground_npm_ai@1.0.0

Malicious code in saps_secplayground_npm_ai (npm)

Analysis

saps_secplayground_npm_ai (all versions 1.0.0–1.0.5) reads /tmp/flag.txt from the installer's filesystem and exfiltrates it to the remote endpoint webhook[.]site/aa236da1-0535-4649-a966-7ea2e62ec9ee. Versions 1.0.4 and 1.0.5 use a postinstall hook (node index.js) to auto-execute on npm install. Exfiltration is performed via HTTPS POST (versions 1.0.0–1.0.4) or GET query parameter (1.0.5) to the same webhook[.]site URL.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 09:26 AM
analyzed
Jun 13, 2026, 09:29 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.