LWA-2026-6963 MAL-2026-12327 ↗ confirmed malware

@offa-uwk/offa-uwk@999.0.6

Malicious code in @offa-uwk/offa-uwk (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1529 · System Shutdown/Reboot

Analysis

Dependency-confusion stub (scoped name @offa-uwk/offa-uwk, version 999.0.6) with a postinstall hook that runs index.js. The script collects the hostname, username, current working directory, and timestamp, then POSTs this metadata as JSON to webhook[.]site/e6b10849-38dc-4280-a8e3-72ab39cfaf65. After exfiltration, it executes shutdown -h now (or systemctl poweroff as fallback) to halt the system. A preinstall hook also writes a marker file to /home/OFFA/flag. The package has no repository, no meaningful description, and ships only a 1.5KB index.js.

analyzed by
Leitwacht
first seen
Jul 20, 2026, 10:55 PM
analyzed
Jul 20, 2026, 10:55 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.