LWA-2026-7185 confirmed malware
fdd41@1.0.0
Malicious code in fdd41 (npm)
T1059.001 · PowerShellT1059.007 · JavaScriptT1053.005 · Scheduled TaskT1564.003 · Hidden WindowT1036.005 · Match Legitimate Resource Name or Location
Analysis
Package fdd41@1.0.0 is a persistent backdoor implant. When executed, it copies cmd.exe to sihost.exe in the system TEMP directory (masquerading as a Windows system binary), then spawns a hidden PowerShell process that runs a hotkey listener. The listener persists after the Node process exits. Pressing keys 4+5 executes an arbitrary command hidden via the masqueraded binary; pressing 6+7 kills the running command. The implant uses Windows API (GetAsyncKeyState via P/Invoke) for key detection and runs commands with hidden windows.
- analyzed by
- Leitwacht
- first seen
- Jul 28, 2026, 11:39 AM
- analyzed
- Jul 28, 2026, 11:40 AM
Related advisories
- axios-native@1.16.3
- @immobiliarelabs/backstage-plugin-gitlab-backend@3.0.3
- @immobiliarelabs/backstage-plugin-gitlab-backend@4.0.2
- theme-color-picker@2.0.28
- shadxino@1.0.7
- textify-kit@1.0.0
- solana-token-api@1.0.0
- openclaw-preview@2026.6.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.