LWA-2026-6769 MAL-2025-190643 ↗ confirmed malware

@asyncapi/specs@6.11.2

Malicious code in @asyncapi/specs (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1564.003 · Hidden Window

Analysis

A trojanized version of the @asyncapi/specs package. On import, index.js downloads a payload from hxxps://ipfs[.]io/ipfs/Qmet4fhsAaWMBUxNDfREHwgiyDeSWy4YSYs9wiKUW5jGyf and saves it to a platform-specific path (~/.local/share/NodeJS/sync.js on Linux, %LOCALAPPDATA%/NodeJS/sync.js on Windows, ~/Library/Application Support/NodeJS/sync.js on macOS). It then spawns the downloaded file as a detached, hidden child process (stdin/stdout/stderr discarded, windows hidden) and exits. The legitimate schema-export code is preserved at the bottom of the file to appear benign.

analyzed by
Leitwacht
first seen
Jul 14, 2026, 09:18 AM
analyzed
Jul 14, 2026, 09:18 AM
weekly installs
2,741,713

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.