LWA-2026-5094 confirmed malware

seek-pass@100.6.0

Malicious code in seek-pass (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

All versions (100.0.0, 100.3.0, 100.6.0, 100.10.0) of seek-pass run a preinstall hook (node index.js) that performs extensive system reconnaissance: probes cloud metadata endpoints (hxxp://169[.]254[.]169[.]254/latest/meta-data/, hxxp://metadata[.]google[.]internal/, hxxp://100[.]100[.]100[.]200/latest/meta-data/) for AWS, GCP, and Alibaba credentials; probes Kubernetes API (kubernetes.default.svc); probes internal services (intranet, gitlab.internal, jenkins.internal, corporate.local). It collects hostname, FQDN, OS/distro/kernel, container type, network interface details (IPs, MAC addresses, netmasks), user/group info, sudo capability, DNS search domains, corporate environment variables (VPN, PROXY, LDAP, ACTIVE_DIRECTORY), SSL certificate subjects, and git repository metadata. All evidence is POSTed as JSON to hwoapraaaotwtsnourpqddszm5n3kkhvo[.]oast[.]fun:443/seek-pass via HTTPS with custom headers (X-Evidence-Proof, X-Source-Hostname, X-Source-User) and a SHA-256 proof hash. The earlier version (100.0.0) exfiltrated hostname/platform/arch as a simpler beacon before the full reconnaissance payload was added.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 05:04 PM
analyzed
Jun 13, 2026, 05:06 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.