LWA-2026-6191 MAL-2026-10893 ↗ confirmed malware

ecto-cargo-wk1tm59a@99.0.0

Malicious code in ecto-cargo-wk1tm59a (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

Package ecto-cargo-wk1tm59a@99.0.0 runs a flag-stealing payload (steal.js) on both preinstall and postinstall hooks. The script reads flag files from common locations (/flag, /flag.txt, /root/flag.txt, /root/flag, /app/flag.txt, /app/flag, /tmp/flag.txt, /home/flag.txt), runs discovery commands (hostname, id, find / -iname "flag*", env | grep flag/htb), and exfiltrates the captured data via HTTP GET to webhook[.]site/9f1b89bd-a22f-4221-b28e-bc956b5ec8e0 with hostname and base64-encoded flag data in query parameters. It also PUTs a JSON-encoded exfil manifest to hardcoded internal service endpoints and to IP 154[.]57[.]164[.]66:30962 at path /api/modules/ECT-987654.

analyzed by
Leitwacht
first seen
Jun 30, 2026, 11:05 PM
analyzed
Jun 30, 2026, 11:06 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.