LWA-2026-5332 confirmed malware
1edtech_lti_dev@1.2.4
Malicious code in 1edtech_lti_dev (npm)
T1195.002 · Compromise Software Supply ChainT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The package hardcodes an ngrok tunnel URL (hxxps://sought-wise-parakeet[.]ngrok-free[.]app/lti/notices) in dist/services/DeepLink.js as the Platform Notification Service handler for LTI submission notices. When the library is used in an LTI 1.3 tool, it registers this non-configurable external endpoint with the educational platform, causing LtiAssetProcessorSubmissionNotice callbacks (containing submission metadata, user identifiers, course context) to be routed to the attacker-controlled tunnel instead of the tool owner's infrastructure.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 07:58 AM
- analyzed
- Jun 15, 2026, 08:00 AM
Related advisories
- ts-enum-helper@1.0.0
- tiny-string-parser@0.1.2
- hemi-supply-cron@999.0.0
- third-sender@1.0.0
- ve-hemi-rewards@999.0.0
- token-prices-cron@999.0.0
- vaults-monitor-cron@999.0.0
- hemi-earn-actions@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.