LWA-2026-5163 confirmed malware

sisubeny-bun-pwn-payload-1@1.0.0

Malicious code in sisubeny-bun-pwn-payload-1 (npm)

T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 Channel

Analysis

The package ships only package.json and README.md, with the malicious payload embedded inline in the postinstall lifecycle hook. On install, the hook runs via `bun -e` and executes: host recon via `whoami`, searches for files named `./flag` or `/flag` and reads their contents, falls back to collecting the current working directory and file listing, then exfiltrates all collected data via HTTP POST to webhooksite[.]net/56efa779-d015-4320-9852-2f44ae981338.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 12:47 AM
analyzed
Jun 14, 2026, 12:56 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.