LWA-2026-5807 confirmed malware

metrics-probe-9b4c@1.0.0

Malicious code in metrics-probe-9b4c (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1053.005 · Scheduled TaskT1552.001 · Credentials In FilesT1555.004 · Windows Credential ManagerT1552.002 · Credentials in RegistryT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

metrics-probe-9b4c@1.0.0 runs a credential-harvesting payload in its preinstall and postinstall hooks (node run.js). On Windows, the payload: 1. Escalates to SYSTEM via a UAC bypass (fodhelper.exe with registry manipulation) 2. Runs a SYSTEM-level PowerShell script that collects: Windows Credential Manager entries (via cmdkey and vaultcmd), LSA secrets from HKLM\SECURITY\Policy\Secrets, SYSTEM environment variables, Azure CLI/MSAL authentication caches from all user profiles, PowerShell history, NuGet/dotnet credential stores, and ProgramData config files containing secrets/tokens/passwords 3. Exfiltrates all collected credentials via HTTPS GET and POST requests to detector-blonde-instructional-circular[.]trycloudflare[.]com:443 at the /beacon endpoint with tss-daas-creds| markers 4. Cleans up the scheduled task and temporary files after execution On non-Windows systems, the payload silently confirms code execution via a beacon to the same host. C2: detector-blonde-instructional-circular[.]trycloudflare[.]com:443, path /beacon?d=tss-daas-creds|...

analyzed by
Leitwacht
first seen
Jun 21, 2026, 01:43 AM
analyzed
Jun 21, 2026, 01:44 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.