LWA-2026-11162 confirmed malware
debug-proxy-chrome-devtools@1.0.2
Malicious code in debug-proxy-chrome-devtools (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel
Analysis
The postinstall hook (install.js) runs a system-reconnaissance sweep on the installing machine — executing id, hostname, uname -a, pwd, env, ps aux, cat /etc/passwd, ls -la /home, ip addr, and ss -tulpn — and POSTs the collected output (including environment variables, which may contain credentials and tokens) as JSON to hxxps://webhook[.]site/cfe35ac2-bec3-48b8-bae1-a49dea5412c2. The package is advertised as Chrome DevTools debug-proxy utilities but performs no such function.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 09:29 AM
- analyzed
- Aug 13, 2026, 09:31 AM
Related advisories
- developer-dashboard@1.0.2
- passkeys-react@1.0.1
- camelot-ammv2-periphery@1.0.0
- @aerodrome-finance/contracts@1.0.0
- global-intel@1.0.1
- @fedfub/string-utils@1.0.0
- dojo-rn-interview@1.0.1
- move-bcs-codec@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.