LWA-2026-11134 confirmed malware

@khaznatech/common@99.0.0

Malicious code in @khaznatech/common (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

@khaznatech/common@99.0.0 is a dependency-confusion stub (scoped name, version 99.0.0, ~1.2KB bundle) whose preinstall hook runs install-report.js. On install it sends the victim's hostname and the current working directory to the webhook[.]site endpoint hxxps://webhook[.]site/93b065ab-227f-4253-b940-361d00e9b870/ via an outbound HTTPS GET, exfiltrating host metadata to an attacker-controlled webhook collector.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 03:59 AM
analyzed
Aug 13, 2026, 03:59 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.