LWA-2026-7310 MAL-2026-12500 ↗ confirmed malware

warp-drive-internal-tooling@99.9.9

Malicious code in warp-drive-internal-tooling (npm)

T1195.002 · Compromise Software Supply ChainT1059.001 · PowerShellT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1204.002 · Malicious File

Analysis

The package's preinstall hook runs a PowerShell command that downloads a remote archive from files.catbox.moe/5khq55[.]zip, extracts it to the system temporary directory, and executes the extracted Verification_Tool.exe with a hidden window. This is a remote download-and-execute dropper that delivers an unknown second-stage payload to Windows systems. The package has no repository, no documented purpose beyond a vague "Internal sync utility" description, and uses an inflated version number (99.9.9) consistent with dependency-confusion targeting.

analyzed by
Leitwacht
first seen
Jul 31, 2026, 06:18 PM
analyzed
Jul 31, 2026, 06:18 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.