LWA-2026-5950 MAL-2026-6395 ↗ confirmed malware

react-campaign-optimizer@1.0.0

Malicious code in react-campaign-optimizer (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.004 · Unix ShellT1082 · System Information DiscoveryT1087 · Account DiscoveryT1016 · System Network Configuration DiscoveryT1049 · System Network Connections DiscoveryT1057 · Process DiscoveryT1046 · Network Service DiscoveryT1083 · File and Directory DiscoveryT1615 · Group Policy DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web Service

Analysis

Postinstall hook (postinstall.js) automatically on install exfiltrates the complete process environment (all secrets, API keys, tokens) and performs deep host/network reconnaissance to an external C2 at 2e3bkumw[.]requestrepo[.]com via HTTPS POST. The script collects: host fingerprint (hostname, OS, platform, CPU count, memory, network interfaces, user info); routing table, ARP cache, DNS configuration, and /etc/hosts contents; running process list, open network sockets, and open file descriptors; cloud metadata from 169[.]254[.]169[.]254 (AWS/Azure/GCP IMDS), 100[.]100[.]100[.]200 (Alibaba), 100[.]64[.]0[.]1 and 169[.]254[.]0[.]23 (Baidu) across 13 paths each including /meta-data/iam/security-credentials/; internal SSRF probing of gateway IPs (10.x, 172.x, 192.168.x) and Kubernetes API endpoints on ports 80/443/6443; TCP port scan of 19 internal services (SSH, MySQL, PostgreSQL, Redis, MongoDB, Elasticsearch, Kafka, Docker, Etcd, etc.); DNS reconnaissance of ~40 internal hostnames (*.baidu[.]com, *.internal, kubernetes.default.svc); sensitive file reads (/etc/passwd, SSH private keys, kubeconfig, Docker config, .npmrc); Kubernetes service account token extraction attempt; and container environment detection. All collected data is JSON-encoded and POSTed to hxxps://2e3bkumw[.]requestrepo[.]com/{path} in phases. C2 host: 2e3bkumw[.]requestrepo[.]com (443/TCP, HTTPS). File paths: package/postinstall.js (the implant).

analyzed by
Leitwacht
first seen
Jun 24, 2026, 08:32 AM
analyzed
Jun 24, 2026, 08:33 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.