Malicious code in lodahsjs (npm)
Description
The npm package 'lodahsjs' version 1.0.0 is a malicious typosquat of the legitimate 'lodash' package. It contains a postinstall script that performs hostile actions including sending system information to a hardcoded command-and-control server and downloading and executing a Windows binary from a suspicious GitHub release. The package has no legitimate functionality and is designed to deliver a malicious payload on Windows and Windows Subsystem for Linux (WSL) environments.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'lodahsjs' npm package (version 1.0.0) is a malicious typosquatting package that mimics the popular 'lodash' package but contains no legitimate exports. Its postinstall.js script executes upon installation and performs two main malicious actions: it sends platform-specific information (including WSL and Linux kernel details) to a hardcoded IP address (http://193.70.34.101:20099/vote), and it downloads an XOR-obfuscated Windows executable from a GitHub release URL (https://github.com/bebraz1/qPzM50V1AKG0rVlH/releases/download/null/main.exe). This executable is saved to the user's temporary directory and launched detached on Windows. On WSL hosts, the script constructs and executes an obfuscated PowerShell command to run the same payload on the Windows side. The package is purely malicious with the intent to select victims and deploy an alien Windows executable from an unrelated personal GitHub account.
Potential Impact
Installation of this package results in execution of malicious code that exfiltrates system information to a remote server and downloads and runs a potentially harmful Windows executable. This can lead to compromise of the affected system, unauthorized data disclosure, and persistence of malicious software. The package does not provide any legitimate functionality, indicating its sole purpose is malicious payload delivery.
Mitigation Recommendations
Since this is a malicious typosquat package, the primary mitigation is to avoid installing 'lodahsjs' and verify package names carefully before installation. There is no official patch or fix because this is not a legitimate package but a malicious actor's artifact. Users and organizations should audit their dependencies to detect and remove this package if present. Use trusted package sources and consider implementing package integrity verification mechanisms. Monitor for and block network connections to the identified C2 IP (193.70.34.101) and the GitHub URL used for payload delivery.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14181
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a85b4cbacd9273b49252e9b
Added to database: 08/19/2026, 13:51:07 UTC
Last enriched: 08/19/2026, 14:53:08 UTC
Last updated: 10/02/2026, 13:52:59 UTC
Views: 24
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.