LWA-2026-5292 confirmed malware
thepackagethatworks_@1.0.2
Malicious code in thepackagethatworks_ (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1552.001 · Credentials In FilesT1567 · Exfiltration Over Web ServiceT1071.001 · Web Protocols
Analysis
The package ships only a package.json with a preinstall lifecycle hook that executes inline JavaScript. The hook reads /tmp/flag.txt from the filesystem, base64-encodes the contents, and exfiltrates them as a query parameter to webhook[.]site/1875238c-b451-44dd-baf0-0560d8c4f3e4 via an HTTPS GET request. This is a targeted file-exfiltration payload delivered through npm install.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 02:48 AM
- analyzed
- Jun 15, 2026, 02:49 AM
Related advisories
- system-driver@1.0.1
- sort-btree@2.1.4
- seed-to-private@1.0.1
- saps_secplayground_npm_ai@1.0.4
- redeem-onchain-sdk@1.0.1
- pino-pretty-logs@1.1.0
- mw-filesystem-events-nodream-es6@0.0.32
- log-input@1.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.