LWA-2026-5730 confirmed malware

env-config-f281@1.0.0

Malicious code in env-config-f281 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.001 · PowerShellT1053.005 · Scheduled TaskT1055 · Process InjectionT1003.004 · LSA SecretsT1555.004 · Windows Credential ManagerT1528 · Steal Application Access TokenT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1012 · Query RegistryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package env-config-f281@1.0.0 executes a credential-theft payload during npm install via both preinstall and postinstall scripts (node run.js). On Windows, it: (1) beacons the hostname and username to the C2 server at cpu-beaches-hay-marketplace[.]trycloudflare[.]com:443; (2) uses the fodhelper.exe UAC bypass (registry key HKCU\Software\Classes\ms-settings\Shell\Open\command) to escalate from user-integrity to SYSTEM; (3) creates a scheduled task running as NT AUTHORITY\SYSTEM that executes a PowerShell payload to dump Windows Credential Manager entries (via cmdkey /list and vaultcmd), LSA secrets from HKLM\SECURITY\Policy\Secrets, Azure CLI / MSAL authentication caches from all user profiles under C:\Users, PowerShell readline history, NuGet credential stores, and all .json/.config/.xml files under C:\ProgramData containing the strings secret, password, token, key, credential, or connectionstring; (4) exfiltrates collected credentials over HTTPS to cpu-beaches-hay-marketplace[.]trycloudflare[.]com via a GET beacon for summaries and a POST beacon for full credential dumps. On non-Windows systems, the payload simply confirms code execution to the same C2. C2 IOC: cpu-beaches-hay-marketplace[.]trycloudflare[.]com:443.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 03:41 PM
analyzed
Jun 18, 2026, 03:42 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.