LWA-2026-5483 confirmed malware
web-examples@55.33.111
Malicious code in web-examples (npm)
T1059.007 · JavaScriptT1082 · System Information Discovery
Analysis
The postinstall hook in this package runs a script that reads the hostname, operating system, and CPU architecture of the system where it is installed. This information is written to a log file inside a hidden directory created at ~/.local/share/package-install/ on Linux or macOS, or at %LOCALAPPDATA%\Proofs\package-install\ on Windows. A dummy shell script is also placed in the same directory. The package has no description and its name does not match its behaviour.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 02:13 AM
- analyzed
- Jun 16, 2026, 02:15 AM
Related advisories
- web3-core-utils@4.3.5
- vue-template-compiler-plugin@2.7.16
- vourfly-tele@4.7.6
- vl-ui-code-preview@10.1.1
- vl-ui-contact-card@10.1.1
- vl-ui-button@10.1.1
- vl-ui-body@10.1.1
- vl-ui-action-group@10.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.