LWA-2026-6043 MAL-2026-5750 ↗ confirmed malware

mailconfirmer@3.3.21

Malicious code in mailconfirmer (npm)

T1059.007 · JavaScriptT1059.001 · PowerShellT1564.003 · Hidden Window

Analysis

The package mailconfirmer@3.3.21 claims to provide email verification utilities but instead runs a postinstall hook (install-hook.js) that spawns a hidden, detached PowerShell process (powershell -NoP -NonI -W Hidden -Enc) executing a base64-encoded payload. The PowerShell window is hidden and the process is detached so it outlives the npm install session and avoids user visibility. The base64-encoded command string is the payload stage; the actual decoded command is not recoverable from the available artifact. The package has no repository and its declared purpose is unrelated to this behaviour.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 10:57 AM
analyzed
Jun 27, 2026, 09:19 PM
weekly installs
8,004

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.