LWA-2026-6707 MAL-2026-10465 ↗ confirmed malware

node-sysmon-native@1.0.0

Malicious code in node-sysmon-native (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1573.001 · Symmetric CryptographyT1041 · Exfiltration Over C2 Channel

Analysis

node-sysmon-native@1.0.0 is a trojanized native addon that masquerades as a system-monitoring package. On install, node-gyp rebuild compiles sysmon[.]cc, which contains an XOR-encoded C2 URL. When the module is required, it spawns a detached pthread that loops fetching commands from the C2 server's /cmd/commands endpoint, executes them via bash -c, and posts the output to /cmd/results. The C2 server is at 152[.]53[.]120[.]90. The package has no repository and its sole purpose is to establish a remote shell on the installer's machine.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 02:09 PM
analyzed
Jul 13, 2026, 02:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.