LWA-2026-5605 MAL-2026-5929 ↗ confirmed malware

backoffice-charges-module@1.999.0

Malicious code in backoffice-charges-module (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

On installation the package runs a preinstall script that automatically executes a bundled script. The script collects host reconnaissance — the package name, a randomly generated execution identifier, the Node.js version, OS platform, and CPU architecture, plus a timestamp — and sends it as a JSON POST to a hardcoded remote endpoint. The package ships no real functionality (the file named as its main entry point is absent); its only behaviour is the install-time outbound beacon. The inflated version number is consistent with a dependency-confusion attempt to override an internal package of the same name.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 08:50 PM
analyzed
Jun 16, 2026, 08:53 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.