LWA-2026-5401 confirmed malware

@sfhbdrffthger/boardstep@1.0.0

Malicious code in @sfhbdrffthger/boardstep (npm)

T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

@sfhbdrffthger/boardstep@1.0.0 is a remote binary dropper. During installation it downloads an executable (tester.exe) from hxxps://www[.]pooron[.]org/tester[.]exe over HTTPS, saves it to the system temp directory, and runs it as a detached background process that survives the installer. The downloaded payload executes independently of Node.js. The C2 host is www[.]pooron[.]org (port 443, TLS).

analyzed by
Leitwacht
first seen
Jun 15, 2026, 03:58 PM
analyzed
Jun 15, 2026, 03:59 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.