LWA-2026-6478 MAL-2026-10038 ↗ confirmed malware

antsrcsrctest@1.0.0

Malicious code in antsrcsrctest (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1613 · Container and Resource DiscoveryT1525 · Implant Internal ImageT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

antsrcsrctest@1.0.0 is a trojanized date-formatting utility whose preinstall hook (node preinstall.js) executes a reconnaissance and exfiltration payload. On install, the script collects the hostname, platform, working directory, and full process environment variables; runs id, whoami, hostname, and ps aux via execSync; checks for container environments by reading /.dockerenv, /proc/1/cgroup, and /proc/self/mountinfo; queries the Alibaba Cloud instance metadata endpoint (hxxp://100[.]100[.]100[.]200/latest/meta-data/) for cloud credentials; and POSTs all collected data to hxxp://101[.]35[.]44[.]248/ and hxxp://101[.]35[.]44[.]248/env.

analyzed by
Leitwacht
first seen
Jul 9, 2026, 03:46 AM
analyzed
Jul 9, 2026, 03:47 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.