LWA-2026-5401 confirmed malware
@sfhbdrffthger/boardstep@1.0.0
Malicious code in @sfhbdrffthger/boardstep (npm)
T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
@sfhbdrffthger/boardstep@1.0.0 is a remote binary dropper. During installation it downloads an executable (tester.exe) from hxxps://www[.]pooron[.]org/tester[.]exe over HTTPS, saves it to the system temp directory, and runs it as a detached background process that survives the installer. The downloaded payload executes independently of Node.js. The C2 host is www[.]pooron[.]org (port 443, TLS).
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 03:58 PM
- analyzed
- Jun 15, 2026, 03:59 PM
Related advisories
- vite-config-field@1.1.0
- dms-backend@1.0.0
- ts-webplug@3.0.5
- tsliverhome@1.1.5
- trgrip@1.0.4
- transform-es2015-destructuring@6.24.1
- texttweak-kit@1.0.0
- stylelint-standard@1.2.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.