LWA-2026-5658 MAL-2026-6328 ↗ confirmed malware

@muaththir/api@2.0.0

Malicious code in @muaththir/api (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

This package has no real functionality. Its package.json declares a preinstall lifecycle hook that silently executes a bundled index.js at install time (output redirected to /dev/null). The script gathers host and user reconnaissance, including the current OS username, working directory, Node.js version, platform and architecture, plus a randomly generated execution id and timestamp, and exfiltrates this data as JSON via an HTTPS POST to an attacker-controlled external endpoint. This runs automatically on npm install with no user interaction.

analyzed by
Leitwacht
first seen
Jun 17, 2026, 05:53 PM
analyzed
Jun 17, 2026, 06:01 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.