LWA-2026-6104 MAL-2026-6555 ↗ confirmed malware

livekit-agents@0.3.4

Malicious code in livekit-agents (npm)

Analysis

The install hook (postinstall: node dist/postinstall.js) collects system information — package name and version, Node.js version, OS platform and architecture, the installer's username, hostname, and current working directory — and sends it via HTTPS POST to livekit-agents[.]xyz:443/api/metrics. The beacon silently suppresses errors and timeouts to avoid detection. The package also declares a self-dependency (livekit-agents@^0.3.1), a known bootstrapping technique.

analyzed by
Leitwacht
first seen
Jun 29, 2026, 05:37 AM
analyzed
Jun 29, 2026, 07:46 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.