LWA-2026-5237 confirmed malware
super-useful-omega-package-123@0.2.1
Malicious code in super-useful-omega-package-123 (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
At install time, the preinstall hook (scripts/preinstall.js) downloads a remote payload from hxxps://rewind[.]secu[.]r[.]ing/setup-b64, triple-base64-decodes it, and executes the decoded content via child_process.execSync() with no output. This gives the remote server arbitrary code execution on the installer's machine with the privileges of the npm install process, enabling credential theft, token harvesting, persistence installation, or any other post-exploitation activity.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 10:32 AM
- analyzed
- Jun 14, 2026, 10:33 AM
Related advisories
- strutil-kit@1.0.0
- streamvault@1.0.1
- st-pathhelper@1.0.0
- stacknova@1.0.0
- sort-btree@2.1.4
- solana-token-api@1.0.0
- snavbox@1.0.1
- sjs-lint-build1@1.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.