LWA-2026-5674 MAL-2026-6092 ↗ confirmed malware

fmt-helpers-794b@1.0.0

Malicious code in fmt-helpers-794b (npm)

Analysis

This npm package executes a payload automatically on installation via both preinstall and postinstall hooks (node run.js). On Linux/CI it enumerates all environment variables and harvests CI/CD and cloud secrets: GitHub Actions tokens (GITHUB_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN/URL, ACTIONS_RUNTIME_TOKEN), NPM_TOKEN, environment AWS credentials, and ECS task-role IAM credentials retrieved from the container credential endpoint at 169[.]254[.]170[.]2. It also probes SSH key files, reads ECS task metadata (task ARN, cluster), performs container-escape reconnaissance (mounts, capabilities, docker socket, init process), and uses the stolen ECS task role to list, describe, and write items to a DynamoDB table. On Windows it performs a fodhelper.exe UAC bypass via an ms-settings registry hijack, registers a SYSTEM-level scheduled task to capture privileged command output and sensitive files, and overwrites a local findings.xml verdict file. All collected data is exfiltrated over HTTPS to a Cloudflare tunnel command-and-control host.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 02:12 AM
analyzed
Jun 18, 2026, 02:26 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.