LWA-2026-11133 confirmed malware
@khaznatech/core@99.0.0
Malicious code in @khaznatech/core (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols
Analysis
The package's preinstall hook runs install-report.js, which performs an outbound HTTPS GET to hxxps://webhook[.]site/93b065ab-227f-4253-b940-361d00e9b870/ appending the machine hostname and the current working directory name. This host-metadata beacon fires on every install, silently, with errors swallowed. The package's actual exported code is trivial string-casing/utility helpers with no network functionality, so the install-time beacon is unrelated to the package's stated purpose.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 03:59 AM
- analyzed
- Aug 13, 2026, 03:59 AM
Related advisories
- @khaznatech/common@99.0.0
- chrome-enterprise-premium-mcp@1.0.0
- broadcast-graphics-mcp@1.0.0
- chromecast-webdriver-cli@1.0.0
- chromeos-webdriver-cli@1.0.0
- gaarf-bq@1.0.0
- gaarf-node@1.0.0
- xbox-one-webdriver-cli@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.