LWA-2026-6468 MAL-2026-7024 ↗ confirmed malware

none123s@0.1.0

Malicious code in none123s (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The package contains a postinstall hook that collects system information (hostname, platform, /etc/hostname, /etc/hosts, /etc/motd, /var/log/cloud-init-output.log, and directory listings of /opt/, /root/, the home directory, and /etc/permiso/) and exfiltrates it via HTTP POST to webhook[.]site/43a8680e-b580-40f5-b7aa-f089ac659712 with the query parameter vendor_identification=1. The package has no other code or functionality.

analyzed by
Leitwacht
first seen
Jul 8, 2026, 06:31 PM
analyzed
Jul 8, 2026, 06:31 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.