comandnpm
comand is a confirmed malicious npm package (MAL-2026-14169) that typosquats a legitimate package to trick installs (malicious version 1.0.0). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in comand (npm)
What this malware does
On npm install, scripts/postinstall.js executes automatically. It first POSTs a JSON body containing the resolved host platform (Windows/MacOS/Linux, with WSL detection) to a hardcoded bare-IP endpoint at http://193.70.34.101:20099/vote; the IP is assembled from a string array (['193','70','34','101'].join('.')) to hide it from static inspection. It then XOR-decodes (key 'stf2026') a hardcoded URL and, on Windows or via a PowerShell bridge from WSL, downloads main.exe from https://github.com/braz1/qPzM50V1AKG0rVlH/releases/download/null/main.exe into %TEMP% and spawns it detached with stdio ignored and windowsHide set. The WSL branch invokes powershell with ExecutionPolicy Bypass through a decoded bridge script. All network destinations and shell command fragments (ADDON_ENC, BRIDGE_LAUNCHER_ENC, BRIDGE_SCRIPT_*_ENC) are stored as XOR-encoded integer arrays reconstructed at runtime via an unpackSegment routine. The GitHub owner (braz1) does not match the npm publisher, the binary is unsigned and unverified, and the package name 'comand' resembles a typosquat of 'command'.
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
TyposquatFind it
Search your lockfiles and build artifacts for comand (version 1.0.0).
If you installed it — respond
comand is a typosquat — you almost certainly intended a legitimately-named package. Remove comand, install the correct package, and rotate any secrets exposed during the install since post-install scripts may have already run.
Did it already run?
If comand was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
Detect & block this
O3 blocks comand-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.