LWA-2026-7207 confirmed malware
test2221@2.2.3
Malicious code in test2221 (npm)
T1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The package contains no executable code — only a package.json file. Both the preinstall and postinstall hooks execute a curl command that collects system information (username via whoami, hostname, current working directory, and directory listing) and sends it to hxxp://54[.]37[.]234[.]136/voicemail as query parameters. The data is exfiltrated on every npm install.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 06:39 AM
- analyzed
- Jul 29, 2026, 06:39 AM
Related advisories
- blots@2.1.0
- @apexfnd/apex@1.0.1
- n8n-nodes-quick-utils@1.0.0
- n8n-nodes-task-runner@1.0.0
- n8n-nodes-devops-utils@1.0.0
- time-format-kit@1.0.2
- string-formatter-pro@1.0.0
- code-formatter-setup@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.