LWA-2026-5513 confirmed malware

withnotification@55.33.111

Malicious code in withnotification (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1074 · Data Staged

Analysis

The package withnotification@55.33.111 runs a postinstall script that writes host metadata (hostname, OS platform, CPU architecture, installation timestamp) to a hidden directory on disk: ~/.local/share/package-install/ on Linux/macOS, and %LOCALAPPDATA%\Proofs\package-install\ on Windows. It also drops a placeholder script file (helper.sh or helper.exe) into that directory. This host-fingerprinting behavior collects system information for reconnaissance purposes. No network exfiltration is performed in this version, but the local staging pattern is consistent with setting up a persistence/beacon directory for later activation.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 04:43 AM
analyzed
Jun 16, 2026, 04:46 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.