luluking3@0.0.1
Malicious code in luluking3 (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
The postinstall hook runs index.js, which decodes a charcode array to build a curl command that downloads a remote JavaScript payload from hxxps://aone-kit[.]oss-cn-beijing[.]aliyuncs[.]com/plugins/crypto[.]js, saves it to a .cache file, executes it via require(), then deletes the file. This is a remote code execution at install time — the C2 host can serve arbitrary malicious payloads.
- analyzed by
- Leitwacht
- first seen
- Jul 24, 2026, 06:26 AM
- analyzed
- Jul 24, 2026, 06:26 AM
Related advisories
- block_package@1.0.0
- rollup-packages-node-polyfills@0.0.1
- tick-forge@11.5.2
- ambera@1.0.0
- gekko-trading-bot@4.2.0
- fastify-client-bundler@1.4.0
- react-tabulix-ui@0.1.2
- encryptstringadmin@1.2.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.