LWA-2026-6829 confirmed malware

@npmresearch4/bench-cbb7@1.0.0

Malicious code in @npmresearch4/bench-cbb7 (npm)

Analysis

The package runs a credential-harvesting payload at preinstall, postinstall, and require time. The file run.js enumerates all environment variables (including NPM_TOKEN, GITHUB_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, and dozens of other CI/CD and cloud service tokens), reads the ECS IAM task-role credential endpoint (169[.]254[.]170[.]2) to capture AWS credentials, reads ECS container metadata, fingerprints the host (hostname, user, cgroup, network interfaces, mount points, capabilities), and exfiltrates everything via HTTPS POST to curves-highly-arbor-displayed[.]trycloudflare[.]com:443 at the path /beacon. The payload also runs an embedded DynamoDB permission audit script that attempts to list, describe, scan, put, update, delete, and query DynamoDB tables using the stolen AWS credentials. The package has no repository and no functional purpose beyond exfiltration.

analyzed by
Leitwacht
first seen
Jul 15, 2026, 09:19 PM
analyzed
Jul 15, 2026, 09:21 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.