LWA-2026-5981 MAL-2026-6487 ↗ confirmed malware

velocityfix@1.0.0

Malicious code in velocityfix (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1070.004 · File Deletion

Analysis

Package 'velocityfix' typosquats the Minecraft Velocity proxy. Its postinstall script (scripts/loader.js) downloads a native executable from store6[.]gofile[.]io/download/web/bcd38d7d-1647-4448-a448-037d58ad9413/payload.exe, saves it to the system temp directory, launches it silently in the background with `start /b`, then deletes the executable after 5 seconds. The package also bundles a copy of the same executable (payload.exe, 1.7 MB) as a fallback. The gofile[.]io host is the external payload source.

analyzed by
Leitwacht
first seen
Jun 25, 2026, 11:35 PM
analyzed
Jun 25, 2026, 11:35 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.