LWA-2026-7008 MAL-2026-12398 ↗ confirmed malware

luluking2@0.0.1

Malicious code in luluking2 (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

The postinstall hook runs index.js which downloads a second-stage payload from hxxps://aone-kit[.]oss-cn-beijing[.]aliyuncs[.]com/plugins/crypto[.]js using curl, saves it to a hidden .cache file, executes it via require(), then deletes the file. The remote host is an Alibaba Cloud OSS bucket in the Beijing region.

analyzed by
Leitwacht
first seen
Jul 22, 2026, 02:21 AM
analyzed
Jul 22, 2026, 02:21 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.