LWA-2026-5781 confirmed malware

kisama-js@0.1.8

Malicious code in kisama-js (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1049 · System Network Connections DiscoveryT1057 · Process DiscoveryT1083 · File and Directory DiscoveryT1071.001 · Web ProtocolsT1573.001 · Symmetric CryptographyT1573.002 · Asymmetric CryptographyT1105 · Ingress Tool TransferT1560.001 · Archive via Utility

Analysis

kisama-js@0.1.8 is a Node.js Remote Access Trojan (RAT) that opens an encrypted command-and-control HTTP+WebSocket server on port 8000. When run, it profiles the host (CPU, memory, disk, OS, kernel version, public IPv4/IPv6 via api[.]ipify[.]org, icanhazip[.]com, checkip[.]amazonaws[.]com, ifconfig[.]me/ip, ipecho[.]net/plain, ipinfo[.]io/ip, myexternalip[.]com/raw, api6[.]ipify[.]org, v6[.]ident[.]me; detects Docker/LXC/Kubernetes/QEMU via cgroup and /proc reads), then exposes remote shell execution (POST /api/exec), full file system access (read/write/upload/download/delete under FILE_ROOT via /api/file/* endpoints), interactive PTY terminal via WebSocket (/api/ws/*), and cron-based task scheduling. C2 traffic is encrypted with ECDSA-signed authentication, ECIES asymmetric encryption, AES-256-GCM session keys, and the Noise Protocol (X25519 key exchange). Default listen address 0[.]0[.]0[.]0:8000; operator configuration via ECDSA_PUBKEY and ECIES_PUBKEY environment variables.

analyzed by
Leitwacht
first seen
Jun 20, 2026, 03:30 AM
analyzed
Jun 20, 2026, 03:31 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.