LWA-2026-6637 MAL-2026-10218 ↗ confirmed malware

pure-folder-three@0.7.3

Malicious code in pure-folder-three (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1059 · Command and Scripting Interpreter

Analysis

The postinstall hook (src/build.js) constructs an obfuscated HTTPS URL from encoded numeric constants and makes a request to a remote C2 server. The response header 'm' is executed as a shell command via child_process.execSync, giving the attacker arbitrary remote code execution on the installer's machine. The payload skips execution if the system username is 'justin' (anti-analysis check). The package is a trojanized directory-tree generator that also bundles unrelated CSS-processing dependencies (postcss, cssnano, purgecss) as cover.

analyzed by
Leitwacht
first seen
Jul 12, 2026, 01:30 PM
analyzed
Jul 12, 2026, 01:35 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.