LWA-2026-6247 MAL-2026-10061 ↗ confirmed malware

cursed-ecto-d3ab00@1.0.0

Malicious code in cursed-ecto-d3ab00 (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1046 · Network Service DiscoveryT1071.001 · Web Protocols

Analysis

All four lifecycle hooks (preinstall, install, postinstall, prepare) execute identical malicious code. On install, the package runs shell commands to read flag files from common paths (/flag*, /root/flag*, /flag.txt, /app/flag*, /srv/flag*, /home/*/flag*, /flag, /run/secrets/*) and environment variables matching "flag" or "htb". It also collects hostname, user id, and working directory. All collected data is base64-encoded and exfiltrated via HTTPS GET to forward-amber-prairie-ruled[.]trycloudflare[.]com/x?d=. Additionally, the package probes a list of internal hosts (127[.]0[.]0[.]1, localhost, app, web, frontend, console, ecto, registry, backend, nginx on ports 3000, 8080, 80, 5000, 4000) and sends a PUT request to /api/modules/ECT-839201 with a JSON manifest declaring the host "PWNED" — attempting to compromise an Ecto application registry.

analyzed by
Leitwacht
first seen
Jul 2, 2026, 11:52 AM
analyzed
Jul 2, 2026, 11:53 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.