LWA-2026-6835 MAL-2026-10749 ↗ confirmed malware

sync-grove@1.0.1

Malicious code in sync-grove (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted Channel

Analysis

The postinstall hook in setup.js downloads an AES-encrypted payload from hxxp://player[.]sweetprovider[.]org/getKey[.]php and a decryption key from hxxp://player[.]sweetprovider[.]org/generateRandomKey[.]php, decrypts it, and executes the result via shelljs.exec(). This gives the remote server arbitrary code execution on the installer's machine.

analyzed by
Leitwacht
first seen
Jul 16, 2026, 07:05 AM
analyzed
Jul 16, 2026, 07:06 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.