LWA-2026-5326 confirmed malware
trgrip@1.0.4
Malicious code in trgrip (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
Package trgrip@1.0.4 combosquats the legitimate is-sorted module and runs a malicious postinstall hook on installation. The hook fetches a remote shell script from reunionistic-keagan-unfestively[.]ngrok-free[.]dev/rev.sh and executes it via bash in a detached background process (exec with detached:true) that persists beyond the npm install lifecycle. The ngrok tunnel URL serves as a dynamic command-and-control endpoint for the second-stage payload.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 06:38 AM
- analyzed
- Jun 15, 2026, 06:40 AM
Related advisories
- transform-es2015-destructuring@6.24.1
- texttweak-kit@1.0.0
- stylelint-standard@1.2.0
- sisubeny-bun-pwn-payload-1@1.0.0
- codyx-ai@1.14.42
- rollup-packages-polyfill-core@0.5.0
- houzidawang808@1.0.0
- redeem-onchain-sdk@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.