titan-exchange-shared-permissions@99.9.9
Malicious code in titan-exchange-shared-permissions (npm)
T1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The postinstall hook runs index.js, which collects the installer's username, current working directory, hostname, and local IP address and POSTs them as JSON to hxxps://webhook[.]site/452b7e38-183d-4652-847d-0f2fa05b9389 on every install. This is a host-metadata beacon that exfiltrates system information to an external webhook endpoint.
- analyzed by
- Leitwacht
- first seen
- Aug 7, 2026, 08:49 PM
- analyzed
- Aug 7, 2026, 08:49 PM
Related advisories
- streak-map-kit@1.0.0
- hardhat-cap@2.21.1
- dolyame-ui-focusstatehoc@35.8.1
- dolyame-ui-mediainfohoc@35.8.1
- dolyame-ui-progressline@35.8.1
- dolyame-ui-tabsblock@35.8.1
- @fedfub/string-utils@1.0.0
- streak-kit-map@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.