system-performance-helper@1.0.1
Malicious code in system-performance-helper (npm)
Analysis
The postinstall hook runs install.js, a full-featured infostealer and remote access trojan. It first performs VM/sandbox detection (checks for hypervisor, analysis tools, low memory) and sleeps 5-15 minutes to evade sandbox timeouts. It then establishes a Telegram-bot C2 channel (hardcoded bot token and chat ID in the source) supporting remote shell execution, file upload/download, screenshot capture, webcam capture, microphone recording, and keylogging. The payload steals browser credentials, cookies, history, and credit cards from Chrome, Edge, Brave, Opera, Vivaldi, Chromium, and Firefox. It extracts crypto wallet files from Exodus, Electrum, AtomicWallet, Ledger Live, Bitcoin, Wasabi, Sparrow, Trezor, and MetaMask directories. It steals SSH private keys (id_rsa, id_dsa, id_ed25519), Discord authentication tokens, Telegram Desktop session files, FileZilla FTP credentials, cloud provider credentials, and Wi-Fi passwords. It exfiltrates environment variables matching KEY/SECRET/TOKEN/PASS patterns. It establishes persistence via Windows scheduled tasks and registry Run keys, Linux crontab and systemd service, and macOS launchd plist. It can self-update by fetching a new payload from pastebin[.]com and supports a self-destruct routine that removes persistence artifacts and wipes command history and logs.
- analyzed by
- Leitwacht
- first seen
- Jul 24, 2026, 09:54 AM
- analyzed
- Jul 24, 2026, 09:55 AM
Related advisories
- wormgpt-cli@1.0.1
- stellarfixer@1.0.0
- node-gyp-runtime@1.0.0
- node-env-resolve@1.0.0
- quickbuf@1.0.1
- terminal-kit-tslint-config@20.1.9
- pfp-forms-sme-loan@20.2.1
- tinkoff-fb-service-prefill-profile-contact@20.2.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.