luludawang-kit@0.0.1
Malicious code in luludawang-kit (npm)
T1027 · Obfuscated Files or InformationT1140 · Deobfuscate/Decode Files or Information
Analysis
On postinstall, index.js decodes a char-code array to reveal a remote URL (aone-kit[.]oss-cn-beijing[.]aliyuncs[.]com/plugins/crypto.js), downloads it via curl to a hidden .cache file in the package directory, requires/executes it, then deletes the file. This is a remote payload stager — the downloaded script runs arbitrary code on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Jul 3, 2026, 07:17 AM
- analyzed
- Jul 3, 2026, 07:18 AM
Related advisories
- @marketfront/bannerpopup@7.0.0
- autotel-edge@3.16.13
- autotel-cloudflare@2.18.16
- autotel-devtools@0.1.1
- autotel-mcp@0.1.14
- autotel-subscribers@10.0.1
- creditcard.js@3.0.60
- @immobiliarelabs/backstage-plugin-gitlab@2.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.