LWA-2026-6872 MAL-2026-11002 ↗ confirmed malware

habinger@2.1.6

Malicious code in habinger (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1098.004 · SSH Authorized KeysT1082 · System Information DiscoveryT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel

Analysis

On install, the postinstall hook (node test.js) triggers index.js which performs credential theft and SSH backdoor installation. It scans the filesystem for .env, config.toml, and id.json files and exfiltrates them to hxxp://170[.]205[.]31[.]203:3000/api/v1. It also fetches an SSH public key from hxxp://170[.]205[.]31[.]203:3001/api/ssh-key and appends it to ~/.ssh/authorized_keys, granting persistent SSH access. It then fetches file-scanning patterns from the same C2 (hxxp://170[.]205[.]31[.]203:3001/api/scan-patterns and /api/block-patterns), scans the entire home directory (or all drives on Windows) for matching files, and uploads them via multipart form to hxxp://170[.]205[.]31[.]203:3001/api/v1 along with the victim's username and platform metadata.

analyzed by
Leitwacht
first seen
Jul 17, 2026, 05:35 AM
analyzed
Jul 17, 2026, 05:35 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.