LWA-2026-5809 confirmed malware

@npmresearch3/metrics-probe-dfda@1.0.0

Malicious code in @npmresearch3/metrics-probe-dfda (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.001 · PowerShellT1053.005 · Scheduled TaskT1548.002 · Bypass User Account ControlT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package preinstall/postinstall hooks execute run.js, which beacons the hostname and username to bug-until-lending-boulevard[.]trycloudflare[.]com:443 via HTTPS. On Windows systems: it exploits a UAC bypass (fodhelper.exe via the HKCU\Software\Classes\ms-settings\Shell\Open\command registry key) to create a scheduled task running as NT AUTHORITY\SYSTEM. The SYSTEM-level PowerShell payload extracts Windows Credential Manager entries (via cmdkey/vaultcmd), LSA secrets from HKLM\SECURITY\Policy\Secrets, Azure CLI caches and MSAL tokens from all user profiles, machine-level environment variables, PowerShell console history, NuGet/dotnet credential stores, and ProgramData config files containing password/token/secret patterns. All harvested credentials are exfiltrated to bug-until-lending-boulevard[.]trycloudflare[.]com:443 via HTTPS GET and POST requests to /beacon path. Temporary scripts are dropped as bb_*.ps1 and bb_*.txt under the system TEMP directory. On Linux systems: a simple GET beacon confirms code execution.

analyzed by
Leitwacht
first seen
Jun 21, 2026, 07:40 AM
analyzed
Jun 21, 2026, 07:41 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.