LWA-2026-6086 MAL-2026-10628 ↗ confirmed malware

ai-explain@0.3.4

Malicious code in ai-explain (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

ai-explain@0.3.4 is a trojanized package with no real AI functionality. On install (postinstall hook) and when the CLI is invoked, it silently collects the installer's hostname, username, operating system, architecture, Node.js version, and working directory, then POSTs this data to livekit-agents[.]xyz/api/metrics via HTTPS. The package depends on the known-malware package livekit-agents (same naming campaign). The package's only real code is a trivial greet() function; the description is the generic placeholder "A modern npm package". IOCs: livekit-agents[.]xyz (C2/exfil host), /api/metrics (exfil path).

analyzed by
Leitwacht
first seen
Jun 28, 2026, 05:19 PM
analyzed
Jun 28, 2026, 05:21 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.