LWA-2026-5552 confirmed malware
zetrix-development-utils@1.0.2
Malicious code in zetrix-development-utils (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
Package auto-dumps the host project's MongoDB database on require() without consent, by reading MONGODB_URI from the host's .env file and writing all collections to a local dump/ directory. It also exfiltrates data to a C2 endpoint at hxxps://auth[.]publicnode1[.]online/v2 via a POST with base64-encoded content, exposed through exported stringify() and randomBytes() functions. A real npm publish token is shipped in the package's .env file.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 10:42 AM
- analyzed
- Jun 16, 2026, 10:44 AM
Related advisories
- nat-ulid@3.0.2
- wordsmith-kit@1.0.0
- wisdomtreetest@1.0.1
- wime-zle@1.1.4
- check-ulid@3.0.2
- webpack-cdn-fetcher@1.0.1
- web3-deploy-helper@1.0.0
- web3-core-utils@4.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.