LWA-2026-11637 confirmed malware
omniauth-recharge-rails-example@1.0.0
Malicious code in omniauth-recharge-rails-example (npm)
T1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The package's preinstall hook runs `wget` against hxxps://webhook[.]site/26e65e9b-fd9c-4f3f-beb3-063309f4d7d9/ and exfiltrates the installer's username (`whoami`), current working directory (`pwd`), and hostname (`hostname`) as query parameters on every install. The same beacon is also wired into the `test` script. This is an install-time host-recon beacon that reports system identity to an external webhook endpoint.
- analyzed by
- Leitwacht
- first seen
- Aug 26, 2026, 07:07 AM
- analyzed
- Aug 26, 2026, 07:07 AM
Related advisories
- hydration-vli-ui@1.0.0
- bamru@1.0.0
- r4wk-book@2.2.2
- hydration-cls-ui@1.0.0
- dim-hydration-ui@1.0.0
- dims-hydration-ui@1.0.0
- @atfm/atfm-material-ui@99.99.99
- js-soul@1.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.