LWA-2026-6724 MAL-2026-10598 ↗ confirmed malware

monitoring-service-util@1.0.0

Malicious code in monitoring-service-util (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1105 · Ingress Tool Transfer

Analysis

On install, monitoring-service-util@1.0.0 executes a base64-encoded payload that steals the NPM_TOKEN environment variable, archives the victim's /root/.codex directory, and publishes the stolen codebase as node-fsagent@5.0.<timestamp> to the npm registry using the stolen token. The payload writes a .npmrc file with the stolen token for authentication and logs its activity to /tmp/.sysmon.log. This is a self-propagating worm that uses the victim's own npm credentials to exfiltrate their codebase and re-publish it under the attacker's package name.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 09:31 PM
analyzed
Jul 13, 2026, 09:32 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.