LWA-2026-5550 MAL-2026-5880 ↗ confirmed malware

nat-ulid@3.0.2

Malicious code in nat-ulid (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1543.002 · Systemd ServiceT1547.001 · Registry Run Keys / Startup FolderT1053.005 · Scheduled TaskT1027 · Obfuscated Files or InformationT1552.001 · Credentials In FilesT1555.003 · Credentials from Web BrowsersT1552.004 · Private KeysT1082 · System Information DiscoveryT1115 · Clipboard DataT1113 · Screen CaptureT1056.001 · KeyloggingT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel

Analysis

A trojanized clone of the legitimate `ulid` identifier library, published under the combosquat name `nat-ulid`. On install, the postinstall script runs a dropper (`dist/node/utils.js`) that copies a 962KB payload (`payload.js`) into a hidden directory (`MicrosoftSystem64` under the user's local data folder) and establishes persistence via Windows scheduled tasks/registry Run key, macOS launchd, or Linux systemd user service/desktop autostart. The payload is a full-featured information-stealer and remote access trojan (RAT): it harvests SSH private keys (id_rsa, id_ed25519), environment variables including NPM_TOKEN, GITHUB_TOKEN, and other secrets, .env files, browser credential stores (Chrome, Edge, Firefox, Brave, Opera, Vivaldi), cryptocurrency wallet directories (Exodus, Electrum, MetaMask), macOS keychain, shell history, and Telegram session data. It also operates a keylogger, clipboard monitor, and screenshot capture system. All stolen data is exfiltrated to a remote C2 server over WebSocket and HTTPS to XOR-obfuscated server URLs via API endpoints under `/api/validate/` and `/api/screenshot/`. The implant also supports arbitrary remote command execution, binary deployment, and full remote terminal control. The package exits early on machines with fewer than 5 CPU cores to evade sandbox analysis.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 10:09 AM
analyzed
Jun 16, 2026, 10:10 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.