LWA-2026-5304 confirmed malware

totally-safe-util@1.0.1

Malicious code in totally-safe-util (npm)

T1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1552.004 · Private KeysT1552.001 · Credentials In FilesT1082 · System Information Discovery

Analysis

Postinstall hook runs 'node setup.js' which executes two curl|bash commands to download and run remote payloads from example[.]com/payload.sh and 185[.]44[.]32[.]1/payload.sh. The setup.js script also reads the GITHUB_TOKEN environment variable and probes ~/.ssh/id_rsa (likely for exfiltration to the second-stage payload). The package is a two-stage downloader that fetches an external shell script upon installation.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 05:18 AM
analyzed
Jun 15, 2026, 05:20 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.