LWA-2026-5727 MAL-2026-6134 ↗ confirmed malware

panrouter-admin@5.0.0

Malicious code in panrouter-admin (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel

Analysis

A C2 implant disguised as a network administration tool. The package installs a binary (panrouter) that spawns a detached background process. A bundled WebSocket relay client (relay_client.cjs) connects to wss://jiuling[.]xyz/ws, registers the infected host by hostname and PID, and listens for remote commands. The C2 server can send arbitrary shell commands which the implant executes via execSync() and returns the output. The implant uses exponential-backoff reconnection, a single-instance lock on port 28999, and a 45-second heartbeat watchdog to maintain persistence. It also proxies AI API traffic through the same infrastructure. DNS and WebSocket connections to jiuling[.]xyz were observed at runtime.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 02:37 PM
analyzed
Jun 18, 2026, 02:38 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.