LWA-2026-6968 MAL-2026-10994 ↗ confirmed malware

app-data-ist@2.1.6

Malicious code in app-data-ist (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 ChannelT1098 · Account ManipulationT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

The package app-data-ist@2.1.6 is a dependency-confusion attack that depends on npm packages named 'child_process' and 'os' (typosquatting Node.js core built-in modules). Its postinstall hook runs a script that: (1) scans the current directory and home directory for credential files (id.json, config.toml, .env) and exfiltrates them via HTTP POST to 170[.]205[.]31[.]203:3000/api/v1; (2) fetches an SSH public key and file-scan patterns from 170[.]205[.]31[.]203:3001/api/ssh-key, /api/scan-patterns, and /api/block-patterns; (3) on Linux, appends the attacker's SSH key to ~/.ssh/authorized_keys, creating a persistent backdoor; (4) scans the entire home directory (or all Windows user drives) for files matching the fetched patterns and batch-uploads them to 170[.]205[.]31[.]203:3001/api/v1. The package description is unrelated to its actual behaviour.

analyzed by
Leitwacht
first seen
Jul 21, 2026, 04:38 AM
analyzed
Jul 21, 2026, 04:38 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.