luluking@0.0.1
Malicious code in luluking (npm)
Analysis
The postinstall hook runs index.js, which uses curl to download a remote JavaScript payload from aone-kit[.]oss-cn-beijing[.]aliyuncs[.]com/plugins/crypto.js and executes it via require(). The downloaded file is saved to a .cache directory in the package root and then deleted after execution. The package has no repository, no description beyond the package name, and its sole purpose is to fetch and run a remote second-stage payload at install time.
- analyzed by
- Leitwacht
- first seen
- Jul 20, 2026, 02:57 AM
- analyzed
- Jul 20, 2026, 02:58 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.