LWA-2026-5364 MAL-2026-5777 ↗ confirmed malware

field-plus@99.99.1

Malicious code in field-plus (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Dependency-confusion stub. On install, both the preinstall and postinstall lifecycle hooks execute a curl command that sends the victim's username, hostname, and working directory to the hardcoded IP address 3[.]7[.]226[.]146 on TCP port 9000 via HTTP GET to the path /callback. The response is discarded and the exit code is swallowed (redirected to /dev/null with `|| true`), making the beacon silent to the installer. The package ships no functional code — only a package.json containing the hooks at version 99.99.1, a sentinel version chosen to take priority over the legitimate field-plus package in automatic resolution.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 10:29 AM
analyzed
Jun 15, 2026, 10:30 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.