LWA-2026-5525 confirmed malware

xboxauthwrapper@3.9.8

Malicious code in xboxauthwrapper (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1102 · Web ServiceT1071.001 · Web ProtocolsT1005 · Data from Local SystemT1041 · Exfiltration Over C2 Channel

Analysis

xboxauthwrapper@3.9.8 is a trojanized npm package that poses as an Xbox authentication utility but is a Discord bot-based Remote Administration Tool (RAT). On import, it fetches an obfuscated Discord bot token and channel configuration from a remote endpoint, decrypts it, and connects to Discord as a bot. It then sends the victim's machine hostname to the attacker's Discord channel (system fingerprinting) and registers chat-command listeners: .runcmd executes arbitrary shell commands on the victim's machine via child_process.exec() and returns output to the attacker; .searchdir lists directory contents; .upload exfiltrates arbitrary files via Discord message attachments. The code is heavily obfuscated with a custom string-encoding layer to evade detection.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 06:43 AM
analyzed
Jun 16, 2026, 06:44 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.