LWA-2026-6975 MAL-2026-11042 ↗ confirmed malware

faust-cont@1.0.0

Malicious code in faust-cont (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.001 · PowerShellT1105 · Ingress Tool TransferT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

The package runs a postinstall hook (node install.js) that collects the hostname, OS type, and architecture, then writes a PowerShell script to the system temp directory and executes it hidden and detached. The PowerShell script installs the Deno runtime (via winget or scoop) and then downloads and executes a remote Deno script from hxxp://172[.]94[.]9[.]157/v028f8cde892b0b74c8[.]js with all permissions (-A flag), giving the attacker full remote code execution on the compromised machine. The package also contains a Telegram beacon function (though the bot token is empty in this version).

analyzed by
Leitwacht
first seen
Jul 21, 2026, 01:32 PM
analyzed
Jul 21, 2026, 01:33 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.