a.poltoradnev-package-c@6.1.10
Malicious code in a.poltoradnev-package-c (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1204.002 · Malicious FileT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
On require(), this package collects a host fingerprint (hostname, username, cwd, Node.js version, PID) and downloads a platform-specific binary payload from Cloudflare Workers subdomains (oob-worker[.]cf...workers[.]dev) with fallback to well1[.]site domains. The binary is written to /var/tmp (or C:\Windows\Temp on Windows) with a random name, made executable, launched as a detached child process, and deleted after 5 seconds. Supported platforms: linux_x64, linux_arm64, darwin, win32. The package has no lifecycle hooks and no repository.
- analyzed by
- Leitwacht
- first seen
- Aug 1, 2026, 11:15 AM
- analyzed
- Aug 1, 2026, 11:17 AM
- weekly installs
- 110
Related advisories
- warp-drive-internal-tooling@99.9.9
- mcp-audit-sync-internal@99.9.9
- native-hello-plugin@1.2.0
- streak-metric-core@1.0.0
- react-fast-refresh-helper@1.2.6
- express-middle@5.5.1
- streak-cal-core@1.0.0
- streak-view-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.