LWA-2026-5707 MAL-2026-6351 ↗ confirmed malware

delta-time-32bb@1.0.0

Malicious code in delta-time-32bb (npm)

T1059.007 · JavaScriptT1053.005 · Scheduled TaskT1070 · Indicator RemovalT1552.001 · Credentials In FilesT1552.005 · Cloud Instance Metadata APIT1082 · System Information DiscoveryT1613 · Container and Resource DiscoveryT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package runs a preinstall and postinstall hook (node run.js) that collects the full environment of the install target and sends it to a remote server. On Linux it reads all environment variables including GITHUB_TOKEN, NPM_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, SSH key paths, container metadata (/proc/1/cgroup, /proc/1/cmdline), network interfaces, Docker socket presence, and the ECS IAM credentials endpoint (169[.]254[.]170[.]2) — then POSTs the data to screw-daisy-powder-pirates[.]trycloudflare[.]com/beacon. It additionally attempts DynamoDB operations using the captured AWS task role. On Windows it locates and overwrites detection-verdict findings, then escalates to SYSTEM via fodhelper.exe and a scheduled task, exfiltrating system-context data to the same C2 host.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 03:54 AM
analyzed
Jun 18, 2026, 10:29 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.