LWA-2026-10992 MAL-2026-13744 ↗ confirmed malware

@dgn-src-click-to-pay-org/srcdcfreleasecert@999.0.1

Malicious code in @dgn-src-click-to-pay-org/srcdcfreleasecert (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

The package's postinstall hook (scripts/check-env.js) runs on install and sends a covert host-metadata beacon to hxxp://16-171-38-148[.]sslip[.]io:8080/api/install (IP 16[.]171[.]38[.]148:8080). The JSON payload contains the package name/version, the installer's operating system platform, CPU architecture, and Node.js version. This network callback is undocumented and unrelated to the package's declared payment-utility purpose (amount formatting, PAN masking, Luhn validation). The endpoint can be redirected via the DGN_SRC_ENDPOINT environment variable.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 05:26 PM
analyzed
Aug 11, 2026, 05:29 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.