LWA-2026-6329 confirmed malware
agn-terminal@0.1.0
Malicious code in agn-terminal (npm)
T1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
agn-terminal@0.1.0 is a trojanized ANSI color helper. On import (require or import), both the ESM entry (src/index.js) and CJS entry (cjs/src/index.js) execute a curl|sh command that downloads a remote script from hxxps://remote[.]agyn[.]org/remote[.]sh and pipes it to sh, with a tracking callback to hxxps://tracker[.]bvgroup[.]co/remote/t42xNzaT2SnXbS_PsZ3gKDY-keTufZ2J. The package has no lifecycle hooks — the payload runs at require-time via top-level code.
- analyzed by
- Leitwacht
- first seen
- Jul 5, 2026, 03:28 PM
- analyzed
- Jul 5, 2026, 03:28 PM
Related advisories
- zod-pino434@1.0.128
- zod-pino434@1.0.127
- paperclip2@1.0.0
- chai-redirection@0.0.1
- vps-maintenance-paperclip-adapter@0.1.1
- express-ini@12.1.10
- compose-logger-stand@1.0.126
- chain-chai-await@1.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.