LWA-2026-5892 confirmed malware

ollama-helpers@0.2.1

Malicious code in ollama-helpers (npm)

T1195 · Supply Chain CompromiseT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

ollama-helpers is a combosquat package impersonating the legitimate Ollama LLM SDK. On install, its postinstall script collects developer identity — hostname, username, git email (from ~/.gitconfig and ~/.config/git/config), GitHub login and email (from ~/.config/gh/hosts.yml), current working directory path, CI provider environment variables, GIT_AUTHOR_EMAIL/GIT_COMMITTER_EMAIL env vars, and runtime platform info — and POSTs it to npm-package-logger-228835561205[.]europe-west1[.]run[.]app over HTTPS. The package ships a publish script that deliberately creates a fake version history to appear maintained. The source utility files (health-check, cache, connection-pool, etc.) are benign stubs; the entire malicious behaviour is in scripts/postinstall.js.

analyzed by
Leitwacht
first seen
Jun 23, 2026, 01:47 PM
analyzed
Jun 23, 2026, 01:48 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.