LWA-2026-0234 confirmed malware

@digininja/postinstall@1.0.1

Malicious code in @digininja/postinstall (npm)

Analysis

The package's postinstall hook runs setup.js, which performs DNS-based exfiltration: it reads the MY_SECRET_API_KEY environment variable and tunnels it via a DNS lookup to a subdomain of the form [apiKey].6u1s7jd9esbax66anvpcg34jgam1asyh[.]collab[.]digi[.]ninja, and also emits a DNS beacon on every install. This is a DNS-tunnelling credential-exfiltration pattern.

analyzed by
Leitwacht
first seen
May 27, 2026, 05:29 AM
analyzed
May 27, 2026, 05:29 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.