LWA-2026-7323 MAL-2026-11505 ↗ confirmed malware

accounts-loading-state@8.9.4

Malicious code in accounts-loading-state (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1204.002 · Malicious File

Analysis

accounts-loading-state@8.9.4 is a remote binary downloader disguised as a microservice utility. On require, it collects a host fingerprint (hostname, username, cwd, Node.js version, PID) and downloads a platform-specific binary from Cloudflare Workers-based C2 infrastructure (oob-worker[.]cf subdomains on workers[.]dev, with well1[.]site as fallback). The binary is written to /var/tmp (or %TEMP% on Windows), made executable, and spawned as a detached process that outlives the parent. Platform-specific download paths: /pkg/package (linux x64), /pkg/package-arm64 (linux arm64), /pkg/loader_mac (macOS), /pkg/package.exe (Windows). The C2 domains are constructed from split strings to evade static detection.

analyzed by
Leitwacht
first seen
Aug 1, 2026, 11:15 AM
analyzed
Aug 1, 2026, 11:20 AM
weekly installs
112

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.