LWA-2026-5292 confirmed malware

thepackagethatworks_@1.0.2

Malicious code in thepackagethatworks_ (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1552.001 · Credentials In FilesT1567 · Exfiltration Over Web ServiceT1071.001 · Web Protocols

Analysis

The package ships only a package.json with a preinstall lifecycle hook that executes inline JavaScript. The hook reads /tmp/flag.txt from the filesystem, base64-encodes the contents, and exfiltrates them as a query parameter to webhook[.]site/1875238c-b451-44dd-baf0-0560d8c4f3e4 via an HTTPS GET request. This is a targeted file-exfiltration payload delivered through npm install.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 02:48 AM
analyzed
Jun 15, 2026, 02:49 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.