LWA-2026-5304 confirmed malware
totally-safe-util@1.0.1
Malicious code in totally-safe-util (npm)
T1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1552.004 · Private KeysT1552.001 · Credentials In FilesT1082 · System Information Discovery
Analysis
Postinstall hook runs 'node setup.js' which executes two curl|bash commands to download and run remote payloads from example[.]com/payload.sh and 185[.]44[.]32[.]1/payload.sh. The setup.js script also reads the GITHUB_TOKEN environment variable and probes ~/.ssh/id_rsa (likely for exfiltration to the second-stage payload). The package is a two-stage downloader that fetches an external shell script upon installation.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 05:18 AM
- analyzed
- Jun 15, 2026, 05:20 AM
Related advisories
- tiny-string-parser@0.1.2
- third-sender@1.0.0
- signature-transaction@1.1.0
- sickle-wrapper@0.2.0
- rtms-manager@1.2.0
- rtms-manager-dev@1.3.0
- houzidawang806@1.0.1
- @ci-lifecycle-test/postinstall-ping@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.