LWA-2026-7236 MAL-2026-11542 ↗ confirmed malware

osinthell@1.9.5

Malicious code in osinthell (npm)

T1059.007 · JavaScriptT1059.003 · Windows Command ShellT1485 · Data DestructionT1491 · DefacementT1490 · Inhibit System RecoveryT1499 · Endpoint Denial of ServiceT1561 · Disk WipeT1489 · Service StopT1070 · Indicator RemovalT1529 · System Shutdown/RebootT1498 · Network Denial of Service

Analysis

osinthell@1.9.5 is a destructive wiper targeting Windows systems. The package exports a `sorgu()` function that triggers 26 modules performing: MBR wipe (writes zeros to \\.\PhysicalDrive0), deletion of C:\ and System32 files, termination of critical processes (explorer.exe, dwm.exe, csrss.exe, winlogon.exe), fork bombs spawning hundreds of detached cmd/powershell/node processes, memory exhaustion via large buffer allocations, disk fill with 100MB files, deletion of boot files (boot.ini, bootmgr), deletion of SAM and SECURITY registry hives, corruption of the hosts file to block google[.]com/discord[.]com/github[.]com/youtube[.]com/reddit[.]com/microsoft[.]com/windows[.]com, disabling boot recovery via bcdedit, formatting C:, truncating all files on C:\ through F:\, deleting Program Files and Users directories, overwriting pagefile.sys and hiberfil.sys, spawning infinite ping loops, and forced system shutdown. Also includes full-screen image defacement via PowerShell/mshta/Internet Explorer/VBScript using a bundled image file. No lifecycle hooks — the payload runs only when the exported function is called.

analyzed by
Leitwacht
first seen
Jul 29, 2026, 10:17 PM
analyzed
Jul 29, 2026, 10:18 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.