LWA-2026-5581 confirmed malware

wm-pause-lib-after-storage@1.0.0

Malicious code in wm-pause-lib-after-storage (npm)

T1071.001 · Web Protocols

Analysis

This package contains no legitimate functionality. On load, index.js shells out to read the local /etc/passwd file into a temporary file, then uploads that file via an HTTP POST to a hardcoded remote IP address on a non-standard port. The current username and hostname are embedded in the request URL path, leaking system identity alongside the password-file contents to an attacker-controlled server.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 04:43 AM
analyzed
Jun 16, 2026, 04:55 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.