LWA-2026-6650 confirmed malware

@npmresearch3/bench-ee3e@1.0.0

Malicious code in @npmresearch3/bench-ee3e (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1053.005 · Scheduled Task

Analysis

The package runs a preinstall/postinstall hook (node run.js) that harvests credentials and exfiltrates them to a remote server. On Linux/CI environments it reads GITHUB_TOKEN, NPM_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, and AWS_SESSION_TOKEN from environment variables; fetches IAM credentials from the ECS metadata endpoint (169[.]254[.]170[.]2); checks for SSH keys under /root/.ssh and /home/runner/.ssh; probes DynamoDB tables using the task role; and sends all collected data via HTTPS POST to economics-alexandria-davis-parallel[.]trycloudflare[.]com:443. On Windows it attempts UAC bypass via the fodhelper registry key (HKCU\Software\Classes\ms-settings\Shell\Open\command) and creates a scheduled task running as SYSTEM to exfiltrate whoami output to the same C2 host. The package has no repository and no documented legitimate purpose.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 02:08 AM
analyzed
Jul 13, 2026, 02:09 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.