LWA-2026-7192 confirmed malware

@ghost_debugger/nanocache@0.1.1

Malicious code in @ghost_debugger/nanocache (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1082 · System Information Discovery

Analysis

@ghost_debugger/nanocache is a trojanized npm package that poses as a zero-dependency LRU/TTL cache but bundles a Windows remote-access trojan. On import, the module automatically spawns vendor/nanocache.exe (a "Screen Monitor Agent" RAT) with detached process, hidden console, and no parent-process linkage. The executable connects to a WebSocket command-and-control server at wss://screen-monitoring-es32[.]onrender[.]com/ws/agent and an HTTP endpoint at hxxps://screen-monitoring-es32[.]onrender[.]com. It supports screen capture via GDI+, server-pushed updates, remote disconnect commands, and reconnection with retry. The binary registers a mutex (Local\ScreenMonitorAgentMutex) to prevent multiple instances and includes --uninstall functionality. Only Windows systems are affected; on other platforms the binary launch is skipped.

analyzed by
Leitwacht
first seen
Jul 28, 2026, 02:08 PM
analyzed
Jul 28, 2026, 02:09 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.