LWA-2026-5243 confirmed malware

system-drive@1.0.0

Malicious code in system-drive (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1543.002 · Systemd ServiceT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1071.001 · Web ProtocolsT1102 · Web ServiceT1041 · Exfiltration Over C2 Channel

Analysis

system-drive@1.0.0 installs a persistent backdoor that exposes all user home directories over the internet. When run, the package writes a JavaScript payload that starts an HTTP file server (with basic auth credentials systum/systum) serving /Users (macOS/Linux) or C:\Users (Windows). It opens a public tunnel via localtunnel[.]me and sends the tunnel URL to linksaver-psi[.]vercel[.]app/api/save. It then installs pm2 and configures the payload to restart automatically on system boot. This gives the attacker remote access to all user files including .ssh keys, .aws credentials, and .npmrc tokens.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 01:03 PM
analyzed
Jun 14, 2026, 01:03 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.