LWA-2026-6005 MAL-2026-6527 ↗ confirmed malware

@immobiliarelabs/backstage-plugin-gitlab-backend@4.0.2

Malicious code in @immobiliarelabs/backstage-plugin-gitlab-backend (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.004 · Unix ShellT1204.002 · Malicious FileT1027 · Obfuscated Files or InformationT1036.005 · Match Legitimate Resource Name or Location

Analysis

@immobiliarelabs/backstage-plugin-gitlab-backend@4.0.2 is a trojanized clone of the legitimate Backstage GitLab plugin. The package ships a clean plugin entry point in dist/index.cjs.js and a hidden malicious payload in package/index.js — a 5.3 MB file containing a ROT13-cipher-obfuscated eval payload. At install time, package/binding.gyp executes node index.js via the GYP <!() shell-command syntax (node-gyp rebuild), suppressing all output with >/dev/null 2>&1. The payload file and binding.gyp are excluded from the package.json "files" allowlist, confirming they were injected into the tarball after the legitimate build step.

analyzed by
Leitwacht
first seen
Jun 26, 2026, 03:20 PM
analyzed
Jun 26, 2026, 03:24 PM
weekly installs
10,854

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.