LWA-2026-6400 MAL-2026-7009 ↗ confirmed malware

configration@2.3.5

Malicious code in configration (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1552.001 · Credentials In Files

Analysis

configration@2.3.5 is a typosquat of "configuration". When required, index.js spawns a detached child process running lib/initializeCaller.js, which POSTs all environment variables (process.env) to a C2 endpoint at hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/6c1d60d35852ef0c05df, then executes arbitrary code returned by the C2 server via new Function("require", response.data). The payload retries up to 5 times and suppresses console output during the operation. This exfiltrates credentials, API keys, and tokens from the environment and enables remote code execution on the installer's machine.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 12:22 PM
analyzed
Jul 7, 2026, 12:23 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.