LWA-2026-5170 MAL-2026-5848 ↗ confirmed malware

slow-surf@10.0.0

Malicious code in slow-surf (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

slow-surf@10.0.0 runs a preinstall hook (node notify.js) that collects system information — hostname, username, current working directory, NODE_ENV, and CPU architecture — and exfiltrates it via HTTPS POST to webhook[.]site/4d0cc13d-a185-4e95-92dc-f4681125055c. The payload is a host-metadata beacon that fingerprints the installation environment.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 01:03 AM
analyzed
Jun 14, 2026, 01:04 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.