LWA-2026-7078 MAL-2026-12399 ↗ confirmed malware

luluking3@0.0.1

Malicious code in luluking3 (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

The postinstall hook runs index.js, which decodes a charcode array to build a curl command that downloads a remote JavaScript payload from hxxps://aone-kit[.]oss-cn-beijing[.]aliyuncs[.]com/plugins/crypto[.]js, saves it to a .cache file, executes it via require(), then deletes the file. This is a remote code execution at install time — the C2 host can serve arbitrary malicious payloads.

analyzed by
Leitwacht
first seen
Jul 24, 2026, 06:26 AM
analyzed
Jul 24, 2026, 06:26 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.