LWA-2026-5705 MAL-2026-6352 ↗ confirmed malware

hex-conv-ae7a@1.0.0

Malicious code in hex-conv-ae7a (npm)

T1059.007 · JavaScriptT1059.001 · PowerShellT1552.001 · Credentials In FilesT1552.004 · Private KeysT1552.005 · Cloud Instance Metadata APIT1552 · Unsecured CredentialsT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1041 · Exfiltration Over C2 ChannelT1548.002 · Bypass User Account ControlT1053.005 · Scheduled Task

Analysis

hex-conv-ae7a@1.0.0 contains a credential-harvesting implant in its preinstall, postinstall, and main entrypoint (run.js). During npm install, the script reads all environment variables including NPM_TOKEN, GITHUB_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, CI/CD tokens, and SSH key files, then exfiltrates them via HTTPS POST to auditor-enabling-furthermore-mobiles[.]trycloudflare[.]com:443/beacon. It also probes the ECS container metadata endpoint (169[.]254[.]170[.]2) for IAM role credentials and reads /proc/1/cgroup and /proc/1/cmdline for container escape indicators. On Windows, the payload attempts a UAC bypass via fodhelper and runs a scheduled task as SYSTEM to enumerate and exfiltrate Defender scan results and package tarballs from D:\TRANSFER directories.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 04:12 AM
analyzed
Jun 18, 2026, 10:29 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.