LWA-2026-5708 MAL-2026-6348 ↗ confirmed malware

buffer-wrap-67d7@1.0.0

Malicious code in buffer-wrap-67d7 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.001 · PowerShellT1053.005 · Scheduled TaskT1098 · Account ManipulationT1552.001 · Credentials In FilesT1552.004 · Private KeysT1525 · Implant Internal ImageT1082 · System Information DiscoveryT1016 · System Network Configuration DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1105 · Ingress Tool Transfer

Analysis

Trojanized package published under the nonsense name 'buffer-wrap-67d7' that exfiltrates environment variables, CI/CD credentials, and cloud provider secrets during npm install. In its preinstall and postinstall hooks, the package collects NPM_TOKEN, GITHUB_TOKEN, AWS access keys, SSH key paths, host/network metadata, container escape indicators (cgroup, mounts, capabilities), and ECS task IAM credentials from the AWS container metadata endpoint (169[.]254[.]170[.]2). All data is POSTed as JSON via HTTPS to coaches-participants-pound-feeds[.]trycloudflare[.]com:443/beacon. On Linux it also writes to ~/.ssh/authorized_keys for persistence. On Windows the payload uses the Fodhelper UAC-bypass technique to escalate to SYSTEM, then creates a scheduled task that exfiltrates files from D:\TRANSFER directories and product-config data. The package claims to be an authorized bug-bounty probe, but the code steals the installer's credentials, which exceeds any legitimate security research scope.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 06:20 AM
analyzed
Jun 18, 2026, 10:26 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.