LWA-2026-5711 confirmed malware

color-utils-eee0@1.0.0

Malicious code in color-utils-eee0 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.001 · PowerShellT1548.002 · Bypass User Account ControlT1053.005 · Scheduled TaskT1082 · System Information DiscoveryT1003.001 · OS Credential DumpingT1552.001 · Credentials In FilesT1552.004 · Private KeysT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package color-utils-eee0@1.0.0 runs a credential-harvesting payload on install (preinstall + postinstall scripts). On Windows, it bypasses UAC via the fodhelper.exe registry escalation technique to obtain SYSTEM privileges, then enumerates and exfiltrates Windows Credential Manager entries (cmdkey/vaultcmd), LSA secrets from the registry, Azure CLI and MSAL credential caches for all user profiles, PowerShell console history, NuGet credential stores, and ProgramData configuration files containing secrets/passwords/tokens. All harvested data is exfiltrated to meetings-bios-pot-cameron[.]trycloudflare[.]com:443 via HTTPS GET and POST beacons using the marker string "tss-daas-creds". On Linux, it signals code execution to the same host.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 07:01 AM
analyzed
Jun 18, 2026, 10:32 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.