LWA-2026-5581 confirmed malware
wm-pause-lib-after-storage@1.0.0
Malicious code in wm-pause-lib-after-storage (npm)
T1071.001 · Web Protocols
Analysis
This package contains no legitimate functionality. On load, index.js shells out to read the local /etc/passwd file into a temporary file, then uploads that file via an HTTP POST to a hardcoded remote IP address on a non-standard port. The current username and hostname are embedded in the request URL path, leaking system identity alongside the password-file contents to an attacker-controlled server.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 04:43 AM
- analyzed
- Jun 16, 2026, 04:55 PM
Related advisories
- chai-plugin-kit@5.8.1
- ssr-auth-sync@1.6.16
- zgmiai-claude-code@1.0.56
- zetrix-development-utils@1.0.2
- chai-plugin-helper@1.7.3
- nat-ulid@3.0.2
- yellow-discord-lookup-v1@1.0.3
- xz-c-d@1.5.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.