LWA-2026-7082 confirmed malware

system-performance-helper@1.0.1

Malicious code in system-performance-helper (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1547.001 · Registry Run Keys / Startup FolderT1053.003 · CronT1543.002 · Systemd ServiceT1546.011 · Launch AgentT1497.001 · System ChecksT1497.003 · Time Based EvasionT1070.004 · File DeletionT1070.003 · Clear Command HistoryT1552.001 · Credentials In FilesT1555.003 · Credentials from Web BrowsersT1539 · Steal Web Session CookieT1555 · Credentials from Password StoresT1552.004 · Private KeysT1082 · System Information DiscoveryT1016 · System Network Configuration DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1573 · Encrypted ChannelT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1113 · Screen CaptureT1125 · Video CaptureT1123 · Audio CaptureT1056.001 · Keylogging

Analysis

The postinstall hook runs install.js, a full-featured infostealer and remote access trojan. It first performs VM/sandbox detection (checks for hypervisor, analysis tools, low memory) and sleeps 5-15 minutes to evade sandbox timeouts. It then establishes a Telegram-bot C2 channel (hardcoded bot token and chat ID in the source) supporting remote shell execution, file upload/download, screenshot capture, webcam capture, microphone recording, and keylogging. The payload steals browser credentials, cookies, history, and credit cards from Chrome, Edge, Brave, Opera, Vivaldi, Chromium, and Firefox. It extracts crypto wallet files from Exodus, Electrum, AtomicWallet, Ledger Live, Bitcoin, Wasabi, Sparrow, Trezor, and MetaMask directories. It steals SSH private keys (id_rsa, id_dsa, id_ed25519), Discord authentication tokens, Telegram Desktop session files, FileZilla FTP credentials, cloud provider credentials, and Wi-Fi passwords. It exfiltrates environment variables matching KEY/SECRET/TOKEN/PASS patterns. It establishes persistence via Windows scheduled tasks and registry Run keys, Linux crontab and systemd service, and macOS launchd plist. It can self-update by fetching a new payload from pastebin[.]com and supports a self-destruct routine that removes persistence artifacts and wipes command history and logs.

analyzed by
Leitwacht
first seen
Jul 24, 2026, 09:54 AM
analyzed
Jul 24, 2026, 09:55 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.