LWA-2026-5375 confirmed malware

vitest-pro@7.0.4

Malicious code in vitest-pro (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1053.005 · Scheduled TaskT1543.004 · Launch DaemonT1547.001 · Registry Run Keys / Startup FolderT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1573 · Encrypted Channel

Analysis

vitest-pro combosquats the popular vitest testing framework. The postinstall hook spawns a detached background process that connects to a hardcoded C2 server on port 4556 with a heartbeat every 30 seconds. The implant downloads, extracts, and executes remote binary payloads (HTTP GET from the C2), establishes persistence via Windows scheduled tasks and Startup folder .vbs scripts, macOS launchd plists, and Linux autostart .desktop entries, and checks whether it is running with administrative/elevated privileges (schtasks, sc query). The malicious code is heavily obfuscated with javascript-obfuscator and disguised within a legitimate Nodemailer codebase under lib/utils/smtp-connection/index.js.0.4 to appear established.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 12:13 PM
analyzed
Jun 15, 2026, 12:13 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.