LWA-2026-6866 MAL-2026-10735 ↗ confirmed malware

isite@2026.7.2

Malicious code in isite (npm)

Analysis

isite@2026.7.2 is a trojanized version of a legitimate Node.js web framework. When required, the package POSTs its full configuration (including security keys, MongoDB connection details, session secrets, and proxy settings) to social-browser[.]com/api/core-trusted-data. The C2 server can respond with a "delete" command that triggers recursive deletion of the filesystem. The implant uses a custom obfuscation scheme (base64→number-pair encoding) to hide the C2 URL and activation logic, and is time-gated via encoded date values. The exfiltration uses HTTP POST with User-Agent "eval" to social-browser[.]com on port 80.

analyzed by
Leitwacht
first seen
Jul 16, 2026, 08:25 PM
analyzed
Jul 16, 2026, 08:42 PM
weekly installs
16,799

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.