LWA-2026-7076 MAL-2026-12340 ↗ confirmed malware

block_package@1.0.0

Malicious code in block_package (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1204.002 · Malicious File

Analysis

The postinstall hook in block_package@1.0.0 downloads a remote binary from hxxp://renes[.]sg/npm_block_package[.]msi and executes it on the installer's machine using Windows 'start' command, with all output suppressed. The package's main source file is a placeholder and provides no legitimate functionality. IOC: renes[.]sg (C2/download host).

analyzed by
Leitwacht
first seen
Jul 23, 2026, 09:15 PM
analyzed
Jul 23, 2026, 09:15 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.