LWA-2026-6633 MAL-2026-10217 ↗ confirmed malware

dotnet-runtime-base@1.0.5

Malicious code in dotnet-runtime-base (npm)

T1195.002 · Compromise Software Supply ChainT1059.001 · PowerShellT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1204.002 · Malicious File

Analysis

Combosquat package impersonating .NET runtime infrastructure. On Windows systems, the postinstall hook (install.js) writes a PowerShell script to the temp directory that downloads a remote binary from hxxps://raw[.]githubusercontent[.]com/cphc811-ui/d3d/main/npm-sc-legit[.]exe and executes it with hidden window. The package's index.js exports trivial string-utility functions as a decoy. The downloaded binary is a second-stage payload whose behaviour is unknown but the delivery mechanism is a classic dropper.

analyzed by
Leitwacht
first seen
Jul 12, 2026, 07:09 AM
analyzed
Jul 12, 2026, 07:09 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.