LWA-2026-5552 confirmed malware

zetrix-development-utils@1.0.2

Malicious code in zetrix-development-utils (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Package auto-dumps the host project's MongoDB database on require() without consent, by reading MONGODB_URI from the host's .env file and writing all collections to a local dump/ directory. It also exfiltrates data to a C2 endpoint at hxxps://auth[.]publicnode1[.]online/v2 via a POST with base64-encoded content, exposed through exported stringify() and randomBytes() functions. A real npm publish token is shipped in the package's .env file.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 10:42 AM
analyzed
Jun 16, 2026, 10:44 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.