MAL-2026-6418

    Dashboard / Malicious Package / MAL-2026-6418

    MAL-2026-6418

    Published: 24 Jun 2026Last Modified: 25 Jun 2026

    Summary: Malicious code in leo-aws (npm)

    Details: The `leo-aws` npm package was compromised as part of the Miasma worm campaign targeting the LeoPlatform npm ecosystem. On June 24, 2026, 20 LeoPlatform packages were published within a 3-second window by a threat actor who had taken over the npm account `czirker` belonging to the LeoPlatform organization. The malicious payload is triggered automatically during `npm install` via a `binding.gyp` file using node-gyp command expansion (`<!(node index.js > /dev/null 2>&1 && echo stub.c)`), which bypasses lifecycle script scanners. The replaced `index.js` (~5.2 MB, obfuscated with ROT-N + AES-128-GCM encryption) deploys a multi-stage worm with the following capabilities: - Credential theft: Targets npm, GitHub, PyPI, RubyGems, Kubernetes, HashiCorp Vault, AWS (IAM keys, Secrets Manager, IMDS), 1Password, JFrog Artifactory, and SSH keys. - AI tool targeting: Exfiltrates configuration files for Claude, Cursor, Gemini, and VS Code. - Worm propagation: Enumerates npm packages and auto-publishes version bumps to spread to other maintainers in the ecosystem. - GitHub persistence: Creates orphan `snapshot-<hex>` branches with fake "Dependabot Updates" workflows to maintain access after initial compromise. Any system that installed this version should be considered fully compromised. Rotate all secrets immediately from a separate, clean machine. See the linked SafeDep report for full payload analysis, indicators of compromise, and remediation guidance. Source: amazon-inspector (914680f83c4971cb6bc16c3ef608f4c1e8a73a25769911d5d9076ad91c935f63) The package contains a binding.gyp at the tarball root whose contents use GYP command-expansion syntax (<!(...) / <!@(...)) on line 6. npm implicitly runs `node-gyp rebuild` whenever a binding.gyp is present in the package, even without any declared install/postinstall script, and node-gyp's configure step evaluates <!(...) expressions as shell commands. This causes the embedded command to execute on every `npm install` of leo-aws. The package ships no native C/C++ source files (no.c/.cc/.cpp/.h), so the binding.gyp has no legitimate build purpose — its only effect is to run the embedded shell command at install time. This is functionally equivalent to a postinstall hook and is a well-known supply-chain attack technique for hiding install-time code execution from cursory script-field inspection.

    Affected packages

    Package

    Name: leo-aws

    Purl: pkg:npm/leo-aws

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    2.0.4
    MAL-2026-6418 | CVE-DB