LWA-2026-5536 MAL-2026-6120 ↗ confirmed malware

@caspianph/storyteller@1.1.13

Malicious code in @caspianph/storyteller (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1564.001 · Hidden Files and DirectoriesT1070.004 · File DeletionT1082 · System Information Discovery

Analysis

The package's postinstall script (setup.cjs) contains obfuscated code that disables TLS certificate validation, contacts a hardcoded C2 server at 23[.]254[.]164[.]92:8000 via the path /update/49890878, downloads a second-stage payload, writes it to a temp directory with a random hex filename + '.json' extension, and executes it as a detached, hidden node process. The script then deletes itself to hide its tracks. The package's main entry point (index.js) is a benign "hello world" module serving as a decoy. No credentials or tokens are stolen — this is a remote access trojan that pulls arbitrary code from the C2 upon installation.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 07:59 AM
analyzed
Jun 16, 2026, 08:00 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.