LWA-2026-5332 confirmed malware

1edtech_lti_dev@1.2.4

Malicious code in 1edtech_lti_dev (npm)

T1195.002 · Compromise Software Supply ChainT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package hardcodes an ngrok tunnel URL (hxxps://sought-wise-parakeet[.]ngrok-free[.]app/lti/notices) in dist/services/DeepLink.js as the Platform Notification Service handler for LTI submission notices. When the library is used in an LTI 1.3 tool, it registers this non-configurable external endpoint with the educational platform, causing LtiAssetProcessorSubmissionNotice callbacks (containing submission metadata, user identifiers, course context) to be routed to the attacker-controlled tunnel instead of the tool owner's infrastructure.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 07:58 AM
analyzed
Jun 15, 2026, 08:00 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.