LWA-2026-5483 confirmed malware

web-examples@55.33.111

Malicious code in web-examples (npm)

T1059.007 · JavaScriptT1082 · System Information Discovery

Analysis

The postinstall hook in this package runs a script that reads the hostname, operating system, and CPU architecture of the system where it is installed. This information is written to a log file inside a hidden directory created at ~/.local/share/package-install/ on Linux or macOS, or at %LOCALAPPDATA%\Proofs\package-install\ on Windows. A dummy shell script is also placed in the same directory. The package has no description and its name does not match its behaviour.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 02:13 AM
analyzed
Jun 16, 2026, 02:15 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.