LWA-2026-5182 MAL-2026-11384 ↗ confirmed malware

spectral-corsair@999.999.1000

Malicious code in spectral-corsair (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package spectral-corsair@999.999.1000 is a dependency-confusion stub (version 999.999.1000) that executes install.js on install/postinstall. It searches for CTF flag values in files (/flag, /root/flag, /tmp/flag, ./flag), environment variables (FLAG, FLAG_HTB, HTB_FLAG), and /proc/self/environ, then exfiltrates any captured flag to the C2 host 94[.]237[.]48[.]51:46517 via HTTP PUT to /api/modules/ECT-987654 and HTTP GET to /api/debug?flag=... It also writes the flag to disk at /tmp/spectral_corsair_flag.txt, /tmp/flag.txt, ./flag.txt, and /var/tmp/flag.txt, and outputs it to stdout/stderr for log capture. When no flag is found, it lists the root directory contents for reconnaissance.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 04:33 AM
analyzed
Jun 14, 2026, 04:35 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.