LWA-2026-5972 MAL-2026-6483 ↗ confirmed malware

log-update-ts@0.1.0

Malicious code in log-update-ts (npm)

Analysis

log-update-ts combosquats the real log-update package. Upon execution, it performs four stages of compromise: (1) collects system fingerprint (OS type, IP address, username) and POSTs it to rust-api-jet[.]vercel[.]app/api/validate/system-info; (2) reads the project's .env file and hunts for Polymarket-related configuration files (env.ts, config.ts, createClobClient.ts, clob.ts), exfiltrating credentials and configs to rust-api-jet[.]vercel[.]app/api/validate/project-env; (3) performs a broad filesystem sweep of the home directory searching for .env, .json, .txt, .doc, .docx, and .xlsx files, sending them in batches to rust-api-jet[.]vercel[.]app/api/validate/files; (4) on Linux systems, installs a hardcoded ssh-ed25519 public key into ~/.ssh/authorized_keys for persistent backdoor SSH access. All C2 traffic targets the Vercel-hosted endpoint rust-api-jet[.]vercel[.]app.

analyzed by
Leitwacht
first seen
Jun 25, 2026, 12:40 PM
analyzed
Jun 25, 2026, 12:42 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.