LWA-2026-7101 MAL-2026-11054 ↗ confirmed malware

app-node-layer@2.1.6

Malicious code in app-node-layer (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 ChannelT1098.004 · SSH Authorized KeysT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

The package runs a credential harvester and SSH backdoor on install via its postinstall hook. It scans the filesystem for sensitive files (.env, id.json, config.toml, Config.toml, env) and exfiltrates them to hxxp://95[.]216[.]118[.]146:3000/api/v1. It also fetches an SSH public key from hxxp://95[.]216[.]118[.]146:3001/api/ssh-key, fetches additional file-scanning patterns from the same C2 server, scans the entire home directory (or Windows drives) for files matching those patterns, uploads them to hxxp://95[.]216[.]118[.]146:3001/api/v1, and installs the fetched SSH key into ~/.ssh/authorized_keys, enables the UFW firewall, and opens port 22 for persistent remote access.

analyzed by
Leitwacht
first seen
Jul 24, 2026, 04:41 PM
analyzed
Jul 24, 2026, 04:42 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.