LWA-2026-6721 confirmed malware
node-fsagent@3.69.0
Malicious code in node-fsagent (npm)
T1027 · Obfuscated Files or InformationT1001.002 · Steganography
Analysis
node-fsagent@3.69.0 is a data-smuggling package with no executable code. The package consists solely of a 682KB package.json file whose description field contains a large base64-encoded gzip-compressed blob. The index.js is empty, there are no lifecycle scripts, no bin entries, and no dependencies. The compressed payload hidden in the description metadata is accessible from the npm registry API without downloading the tarball, enabling other packages or scripts to retrieve and decode it.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 08:27 PM
- analyzed
- Jul 13, 2026, 08:29 PM
Related advisories
- react-hot-svg@1.1.5
- theta-sdk-js@1.2.14
- polymarket-mcp-v2@2.1.6
- tslint-conf@7.2.1
- viteplugiin@1.0.28
- express-guardian@1.4.1
- chai-sdk@1.4.7
- zredis-typed@1.0.127
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.