LWA-2026-5172 confirmed malware

snavbox@1.0.1

Malicious code in snavbox (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1106 · Native APIT1027.002 · Software PackingT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1071.001 · Web ProtocolsT1102 · Web ServiceT1105 · Ingress Tool TransferT1573 · Encrypted ChannelT1041 · Exfiltration Over C2 Channel

Analysis

When installed or executed, snavbox downloads multiple binary executables (sing-box proxy, cloudflared tunnel client, and Nezha monitoring agent) from the C2 host amd64[.]ssss[.]nyc[.]mn (paths: /sb, /bot, /agent, /v1). The binaries are stored under .npm/ with randomized 6-character filenames, given execute permissions, and launched as background daemons. The software configures a full proxy server stack (VMess WebSocket, VLESS REALITY, Hysteria2, TUIC, SOCKS5 inbounds) with Cloudflare WARP WireGuard outbound routing, and establishes a Cloudflare tunnel to expose the proxy to the internet. It fingerprints the host (IP address via ipv4[.]ip[.]sb, geo/ISP via api[.]ip[.]sb/geoip and ip-api[.]com/json) and registers with a remote Nezha monitoring dashboard for command-and-control. Generated proxy subscription links are optionally exfiltrated to an UPLOAD_URL endpoint or a Telegram bot (api[.]telegram[.]org) configured via BOT_TOKEN and CHAT_ID environment variables.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 01:47 AM
analyzed
Jun 14, 2026, 01:49 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.