LWA-2026-7185 confirmed malware

fdd41@1.0.0

Malicious code in fdd41 (npm)

T1059.001 · PowerShellT1059.007 · JavaScriptT1053.005 · Scheduled TaskT1564.003 · Hidden WindowT1036.005 · Match Legitimate Resource Name or Location

Analysis

Package fdd41@1.0.0 is a persistent backdoor implant. When executed, it copies cmd.exe to sihost.exe in the system TEMP directory (masquerading as a Windows system binary), then spawns a hidden PowerShell process that runs a hotkey listener. The listener persists after the Node process exits. Pressing keys 4+5 executes an arbitrary command hidden via the masqueraded binary; pressing 6+7 kills the running command. The implant uses Windows API (GetAsyncKeyState via P/Invoke) for key detection and runs commands with hidden windows.

analyzed by
Leitwacht
first seen
Jul 28, 2026, 11:39 AM
analyzed
Jul 28, 2026, 11:40 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.