LWA-2026-6042 MAL-2026-6555 ↗ confirmed malware

livekit-agents@0.3.0

Malicious code in livekit-agents (npm)

T1195.002 · Compromise Software Supply ChainT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Package livekit-agents@0.3.0 is a combosquat impersonating the real @livekit/agents SDK. The postinstall hook ("node scripts/postinstall.js") is declared but the script file is missing from the tarball. The CLI binary (dist/cli.js) POSTs host metadata — Node.js version, platform, and architecture — to livekit-agents[.]xyz/api/metrics, a domain unaffiliated with the legitimate LiveKit project (livekit[.]io). The package ships only a stub greet() function instead of the real SDK code.

analyzed by
Leitwacht
first seen
Jun 27, 2026, 07:57 PM
analyzed
Jun 27, 2026, 07:58 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.