LWA-2026-10650 confirmed malware

mx-www-locales-common@99.0.0

Malicious code in mx-www-locales-common (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook runs a host-fingerprinting beacon. It collects the machine hostname, OS/platform/arch, CPU count, username, home directory, working directory, local IPv4 addresses, public IP (queried from ifconfig[.]me / api[.]ipify[.]org), and a broad set of CI and environment variables (GITHUB_*, GITLAB_CI, AWS_EXECUTION_ENV, npm_config_registry, HOME, PWD, USER, LOGNAME, and others), then exfiltrates the assembled JSON to hxxps://webhook[.]site/e97b40db-c35f-4f98-a2d4-3f94ad5fd668 and to a canarytokens URL (hxxp://canarytokens[.]com/images/traffic/1dgvcz6mx2ec0lb7jda73aujc/post[.]jsp) with hostname/IP/CI-vars/timestamp query parameters. It also writes the fingerprint to /tmp/mexc-confirmation-dios.txt. The package is a single-version 99.0.0 release masquerading as a MEXC internationalization-locales package.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 06:43 PM
analyzed
Aug 6, 2026, 06:43 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.