LWA-2026-5326 confirmed malware

trgrip@1.0.4

Malicious code in trgrip (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

Package trgrip@1.0.4 combosquats the legitimate is-sorted module and runs a malicious postinstall hook on installation. The hook fetches a remote shell script from reunionistic-keagan-unfestively[.]ngrok-free[.]dev/rev.sh and executes it via bash in a detached background process (exec with detached:true) that persists beyond the npm install lifecycle. The ngrok tunnel URL serves as a dynamic command-and-control endpoint for the second-stage payload.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 06:38 AM
analyzed
Jun 15, 2026, 06:40 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.