LWA-2026-11280 confirmed malware

autbank-core@99.0.0

Malicious code in autbank-core (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The preinstall hook (preinstall.js) collects host identity (hostname, platform, architecture, username, home directory, working directory, node version) and harvests environment variables whose names contain KEY, SECRET, TOKEN, PASSWORD, AWS, API, CREDENTIALS, AUTH, or PRIVATE, plus the contents of any .env file and the output of `git remote -v`. It POSTs this data as JSON to 209[.]99[.]185[.]109:8888/npm-exfil, and as a backup encodes the hostname as hex and resolves it as a DNS subdomain of 209[.]99[.]185[.]109. The postinstall hook references a postinstall.js file that is not present in the package.

analyzed by
Leitwacht
first seen
Aug 14, 2026, 03:06 PM
analyzed
Aug 14, 2026, 03:07 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.