LWA-2026-5646 MAL-2026-10871 ↗ confirmed malware

@azure-lab-services/ml-ts@99.0.0

Malicious code in @azure-lab-services/ml-ts (npm)

Analysis

Dependency-confusion package using an Azure-style scoped name and an inflated 99.0.0 version. Its package.json registers a preinstall lifecycle hook that executes a bundled script on install. The script gathers host reconnaissance — hostname, OS platform and architecture, the install working-directory path, a timestamp, and the machine public IP (queried from an external IP-echo service) — and exfiltrates the collected data as a JSON message to a hardcoded Discord webhook. No legitimate functionality is present; the package exists solely to fingerprint and beacon hosts that auto-install it.

analyzed by
Leitwacht
first seen
Jun 17, 2026, 02:12 PM
analyzed
Jun 17, 2026, 02:21 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.