LWA-2026-11162 confirmed malware

debug-proxy-chrome-devtools@1.0.2

Malicious code in debug-proxy-chrome-devtools (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook (install.js) runs a system-reconnaissance sweep on the installing machine — executing id, hostname, uname -a, pwd, env, ps aux, cat /etc/passwd, ls -la /home, ip addr, and ss -tulpn — and POSTs the collected output (including environment variables, which may contain credentials and tokens) as JSON to hxxps://webhook[.]site/cfe35ac2-bec3-48b8-bae1-a49dea5412c2. The package is advertised as Chrome DevTools debug-proxy utilities but performs no such function.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 09:29 AM
analyzed
Aug 13, 2026, 09:31 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.