LWA-2026-5163 confirmed malware
sisubeny-bun-pwn-payload-1@1.0.0
Malicious code in sisubeny-bun-pwn-payload-1 (npm)
T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 Channel
Analysis
The package ships only package.json and README.md, with the malicious payload embedded inline in the postinstall lifecycle hook. On install, the hook runs via `bun -e` and executes: host recon via `whoami`, searches for files named `./flag` or `/flag` and reads their contents, falls back to collecting the current working directory and file listing, then exfiltrates all collected data via HTTP POST to webhooksite[.]net/56efa779-d015-4320-9852-2f44ae981338.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 12:47 AM
- analyzed
- Jun 14, 2026, 12:56 AM
Related advisories
- sickle-wrapper@0.2.0
- pretty-pino-logger@2.0.2
- pretty-fancy@1.0.1
- prettlog@1.0.10
- prettier-logger@0.1.4
- polymarket-onchain-plugin@2.1.3
- pocbitbarrontest@1.0.0
- ect-839201@100.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.