faust-cont@1.0.0
Malicious code in faust-cont (npm)
Analysis
The package runs a postinstall hook (node install.js) that collects the hostname, OS type, and architecture, then writes a PowerShell script to the system temp directory and executes it hidden and detached. The PowerShell script installs the Deno runtime (via winget or scoop) and then downloads and executes a remote Deno script from hxxp://172[.]94[.]9[.]157/v028f8cde892b0b74c8[.]js with all permissions (-A flag), giving the attacker full remote code execution on the compromised machine. The package also contains a Telegram beacon function (though the bot token is empty in this version).
- analyzed by
- Leitwacht
- first seen
- Jul 21, 2026, 01:32 PM
- analyzed
- Jul 21, 2026, 01:33 PM
Related advisories
- quickbuf@1.0.1
- my-tailwind-gutenberg-block@0.1.2
- dotnet-runtime-base@1.0.5
- mailconfirmer@3.3.11
- mailconfirmer@3.3.21
- shadxino@1.0.7
- @npmresearch3/metrics-probe-dfda@1.0.0
- aikaf668897@1.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.