LWA-2026-5982 MAL-2026-6486 ↗ confirmed malware

unsafe-malicious-package@1.0.0

Malicious code in unsafe-malicious-package (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The postinstall hook in scripts/postinstall.js reads the installer's ~/.aws/credentials file and exfiltrates its contents via HTTP POST to 139[.]59[.]87[.]78:8765/listener as a JSON payload containing the timestamp, source identifier, file path, and credential content.

analyzed by
Leitwacht
first seen
Jun 25, 2026, 05:44 PM
analyzed
Jun 25, 2026, 05:45 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.