LWA-2026-6679 MAL-2026-10445 ↗ confirmed malware

node-procmetrics@1.0.6

Malicious code in node-procmetrics (npm)

T1059.007 · JavaScriptT1059.004 · Unix ShellT1071.001 · Web ProtocolsT1053.003 · CronT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1082 · System Information Discovery

Analysis

The postinstall hook in install.js deploys a persistent remote access trojan. It copies itself to /tmp/.pm-agent.js, spawns a detached background process, and installs a crontab entry for persistence. The agent polls hxxp://152[.]53[.]120[.]90/cmd/commands every second for commands, executes them via bash -c, and exfiltrates the output to hxxp://152[.]53[.]120[.]90/cmd/results. The C2 server can push arbitrary shell commands to the infected machine.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 11:54 AM
analyzed
Jul 13, 2026, 11:54 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.