LWA-2026-6329 confirmed malware

agn-terminal@0.1.0

Malicious code in agn-terminal (npm)

T1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

agn-terminal@0.1.0 is a trojanized ANSI color helper. On import (require or import), both the ESM entry (src/index.js) and CJS entry (cjs/src/index.js) execute a curl|sh command that downloads a remote script from hxxps://remote[.]agyn[.]org/remote[.]sh and pipes it to sh, with a tracking callback to hxxps://tracker[.]bvgroup[.]co/remote/t42xNzaT2SnXbS_PsZ3gKDY-keTufZ2J. The package has no lifecycle hooks — the payload runs at require-time via top-level code.

analyzed by
Leitwacht
first seen
Jul 5, 2026, 03:28 PM
analyzed
Jul 5, 2026, 03:28 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.