LWA-2026-6563 MAL-2026-10090 ↗ confirmed malware

nonenull1@1.0.0

Malicious code in nonenull1 (npm)

T1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1083 · File and Directory DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's main entry point (index.js) is a credential harvester. On require(), it POSTs system metadata (hostname, username, platform, Node version, git email) to crabbing-thong-overhung[.]ngrok-free[.]dev/ping, then reads files from ~/.ssh, ~/.aws, ~/.config, ~/.kube, ~/.docker, ~/.gnupg and any .env files in parent directories, collects environment variables matching token/secret/key/pass/auth patterns, and exfiltrates all of it to crabbing-thong-overhung[.]ngrok-free[.]dev/exfil via HTTPS POST.

analyzed by
Leitwacht
first seen
Jul 9, 2026, 03:38 PM
analyzed
Jul 9, 2026, 03:39 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.