LWA-2026-11134 confirmed malware
@khaznatech/common@99.0.0
Malicious code in @khaznatech/common (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols
Analysis
@khaznatech/common@99.0.0 is a dependency-confusion stub (scoped name, version 99.0.0, ~1.2KB bundle) whose preinstall hook runs install-report.js. On install it sends the victim's hostname and the current working directory to the webhook[.]site endpoint hxxps://webhook[.]site/93b065ab-227f-4253-b940-361d00e9b870/ via an outbound HTTPS GET, exfiltrating host metadata to an attacker-controlled webhook collector.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 03:59 AM
- analyzed
- Aug 13, 2026, 03:59 AM
Related advisories
- @khaznatech/core@99.0.0
- chrome-enterprise-premium-mcp@1.0.0
- broadcast-graphics-mcp@1.0.0
- chromecast-webdriver-cli@1.0.0
- chromeos-webdriver-cli@1.0.0
- gaarf-bq@1.0.0
- gaarf-node@1.0.0
- xbox-one-webdriver-cli@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.