LWA-2026-5280 confirmed malware

texttweak-kit@1.0.0

Malicious code in texttweak-kit (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1564.003 · Hidden WindowT1543.003 · Windows ServiceT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1552.001 · Credentials In Files

Analysis

On npm install, the postinstall hook in bin/setup.js spawns assets/setup-helper.exe as a detached hidden background Windows process with no console output. The executable (9.8MB) is a PyInstaller-packed Python binary that bundles requests, urllib3, http.client, socket, ssl, subprocess, multiprocessing, base64, hashlib, hmac, and netrc — a complete C2 implant framework with capabilities for network communication, command execution, and credential access from the victim's machine. The package's JavaScript library at dist/index.js is a decoy string-manipulation library unrelated to the malicious payload. The package does not ship the installer's tokens — the payload is the implanted PE binary itself.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 10:48 PM
analyzed
Jun 14, 2026, 10:49 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.