LWA-2026-5760 MAL-2026-6235 ↗ confirmed malware

yianzzkf6687@1.0.3

Malicious code in yianzzkf6687 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Postinstall hook runs node scripts/postinstall.js which spawns a hidden, detached background process executing scripts/shell.js — a multi-method reverse shell targeting C2 host 114[.]67[.]90[.]67 across ports 3334, 4444, 443, 80, 8080, and 53. The payload uses Node net sockets (spawning /bin/sh -i on Linux or hidden PowerShell.exe on Windows with pipes to the TCP socket), Bash /dev/tcp, and Python 2/3 reverse shells. Additionally, an HTTP GET pingback on port 8333 exfiltrates the hostname, username, working directory, and OS platform/release to the same IP. Logs to /tmp/.npm-cache.log to disguise as npm cache activity. The package's index.js is a harmless decoy string-manipulation library to evade casual inspection.

analyzed by
Leitwacht
first seen
Jun 19, 2026, 08:40 AM
analyzed
Jun 19, 2026, 08:41 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.