LWA-2026-11637 confirmed malware

omniauth-recharge-rails-example@1.0.0

Malicious code in omniauth-recharge-rails-example (npm)

T1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall hook runs `wget` against hxxps://webhook[.]site/26e65e9b-fd9c-4f3f-beb3-063309f4d7d9/ and exfiltrates the installer's username (`whoami`), current working directory (`pwd`), and hostname (`hostname`) as query parameters on every install. The same beacon is also wired into the `test` script. This is an install-time host-recon beacon that reports system identity to an external webhook endpoint.

analyzed by
Leitwacht
first seen
Aug 26, 2026, 07:07 AM
analyzed
Aug 26, 2026, 07:07 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.