LWA-2026-6283 MAL-2026-6999 ↗ confirmed malware

luludawang-kit@0.0.1

Malicious code in luludawang-kit (npm)

T1027 · Obfuscated Files or InformationT1140 · Deobfuscate/Decode Files or Information

Analysis

On postinstall, index.js decodes a char-code array to reveal a remote URL (aone-kit[.]oss-cn-beijing[.]aliyuncs[.]com/plugins/crypto.js), downloads it via curl to a hidden .cache file in the package directory, requires/executes it, then deletes the file. This is a remote payload stager — the downloaded script runs arbitrary code on the installer's machine.

analyzed by
Leitwacht
first seen
Jul 3, 2026, 07:17 AM
analyzed
Jul 3, 2026, 07:18 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.