LWA-2026-11571 confirmed malware

message-compiler@9.2.0

Malicious code in message-compiler (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1071.004 · DNST1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall hook runs vishu.js, which on install exfiltrates host and CI metadata to attacker-controlled endpoints. It fetches the machine's public IP from api[.]ipify[.]org, sends an HTTPS request to hxxps://webhook[.]site/32113f06-42ab-454b-a58f-5a8ea6333c6d with the IP and CI environment variables (CI, GITHUB_ACTIONS, GITHUB_WORKFLOW, GITHUB_RUN_ID, GITHUB_RUN_NUMBER, GITHUB_RUN_ATTEMPT) appended as query parameters, and performs a DNS lookup against ping-<hostname>.your-collab-domain[.]oastify[.]com (a Burp Collaborator interaction domain). The package has no legitimate function requiring network access on install.

analyzed by
Leitwacht
first seen
Aug 23, 2026, 04:55 PM
analyzed
Aug 23, 2026, 04:55 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.