LWA-2026-7132 MAL-2026-11066 ↗ confirmed malware

@ks-radar/radar@21.0.0

Malicious code in @ks-radar/radar (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The package runs a preinstall script that reads a hex-encoded command from a bundled JSON file, decodes it, and executes it. The decoded command uses curl to POST system information (whoami, current working directory, hostname) and the contents of /etc/passwd to a remote webhook endpoint at eobdzec83knbura[.]m[.]pipedream[.]net. This is a system-reconnaissance and data-exfiltration payload that runs at install time without the user's knowledge.

analyzed by
Leitwacht
first seen
Jul 25, 2026, 09:22 PM
analyzed
Jul 25, 2026, 09:23 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.