LWA-2026-7316 MAL-2026-12127 ↗ confirmed malware

a.poltoradnev-package-c@6.1.10

Malicious code in a.poltoradnev-package-c (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1204.002 · Malicious FileT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

On require(), this package collects a host fingerprint (hostname, username, cwd, Node.js version, PID) and downloads a platform-specific binary payload from Cloudflare Workers subdomains (oob-worker[.]cf...workers[.]dev) with fallback to well1[.]site domains. The binary is written to /var/tmp (or C:\Windows\Temp on Windows) with a random name, made executable, launched as a detached child process, and deleted after 5 seconds. Supported platforms: linux_x64, linux_arm64, darwin, win32. The package has no lifecycle hooks and no repository.

analyzed by
Leitwacht
first seen
Aug 1, 2026, 11:15 AM
analyzed
Aug 1, 2026, 11:17 AM
weekly installs
110

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.