LWA-2026-5466 MAL-2026-4711 ↗ confirmed malware

wao@0.41.2

Malicious code in wao (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1552.001 · Credentials In FilesT1082 · System Information Discovery

Analysis

wao@0.41.2 is a trojanized version of the legitimate wao CLI (an Arweave AO computer tool). The preinstall hook executes a 976KB ELF binary (disguised as src/deps.ts) that delivers a Shai-Hulud supply-chain worm payload at install time. The package depends on arjson and hbsig, which are companion malware packages from the same campaign. The worm executes a native binary during npm install with full system access. The publisher has deprecated this version and advises upgrading.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 11:43 PM
analyzed
Jun 15, 2026, 11:48 PM
weekly installs
1,596

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.