wao@0.41.2
Malicious code in wao (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1552.001 · Credentials In FilesT1082 · System Information Discovery
Analysis
wao@0.41.2 is a trojanized version of the legitimate wao CLI (an Arweave AO computer tool). The preinstall hook executes a 976KB ELF binary (disguised as src/deps.ts) that delivers a Shai-Hulud supply-chain worm payload at install time. The package depends on arjson and hbsig, which are companion malware packages from the same campaign. The worm executes a native binary during npm install with full system access. The publisher has deprecated this version and advises upgrading.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 11:43 PM
- analyzed
- Jun 15, 2026, 11:48 PM
- weekly installs
- 1,596
Related advisories
- stylelint-standard@1.2.0
- macos-ci-utils@1.0.1
- react-next-dom@1.1.7
- node-pino@2.3.2
- chai-utils-test@4.5.4
- autotel-mongoose@2.0.5
- autotel-mongoose@3.0.1
- autotel-mongoose@6.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.