LWA-2026-5237 confirmed malware

super-useful-omega-package-123@0.2.1

Malicious code in super-useful-omega-package-123 (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

At install time, the preinstall hook (scripts/preinstall.js) downloads a remote payload from hxxps://rewind[.]secu[.]r[.]ing/setup-b64, triple-base64-decodes it, and executes the decoded content via child_process.execSync() with no output. This gives the remote server arbitrary code execution on the installer's machine with the privileges of the npm install process, enabling credential theft, token harvesting, persistence installation, or any other post-exploitation activity.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 10:32 AM
analyzed
Jun 14, 2026, 10:33 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.