LWA-2026-11133 confirmed malware

@khaznatech/core@99.0.0

Malicious code in @khaznatech/core (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

The package's preinstall hook runs install-report.js, which performs an outbound HTTPS GET to hxxps://webhook[.]site/93b065ab-227f-4253-b940-361d00e9b870/ appending the machine hostname and the current working directory name. This host-metadata beacon fires on every install, silently, with errors swallowed. The package's actual exported code is trivial string-casing/utility helpers with no network functionality, so the install-time beacon is unrelated to the package's stated purpose.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 03:59 AM
analyzed
Aug 13, 2026, 03:59 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.