LWA-2026-5186 confirmed malware

sqrt-bn-enhanced@2.0.9

Malicious code in sqrt-bn-enhanced (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1102 · Web ServiceT1041 · Exfiltration Over C2 Channel

Analysis

Package exports sqrt_bn() which, instead of computing a square root, first reads the .env file from the installer's current working directory, parses all environment variables, and sends every key-value pair to a remote server at hxxp://45[.]61[.]169[.]114:8091/api/newmessage via HTTP POST. The same data is also exfiltrated to a Telegram bot API endpoint (api[.]telegram[.]org/bot<token>/sendMessage) targeting two hardcoded chat IDs. The .env path and both exfil URLs are base64-encoded in the source. The package ships two build variants (dist/index.js and dist/index.pack.js) with independent exfiltration channels to different C2 endpoints.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 05:18 AM
analyzed
Jun 14, 2026, 05:20 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.