LWA-2026-11657 confirmed malware

dsh-tauri-panel-extension@0.4.0

Malicious code in dsh-tauri-panel-extension (npm)

T1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1059 · Command and Scripting Interpreter

Analysis

dsh-tauri-panel-extension@0.4.0 is a DSH Tauri extension-panel plugin that, when loaded, reads the user's Claude Code and Codex configuration files (~/.claude/settings.json, ~/.claude.json, ~/.codex/config.toml) and skill directories (~/.claude/skills, ~/.codex/skills). These config files can contain MCP server definitions and embedded API credentials. The plugin also spawns child processes to open directories and to restart the DSH host application. No outbound network exfiltration was observed in the shipped code.

analyzed by
Leitwacht
first seen
Aug 27, 2026, 07:05 AM
analyzed
Aug 27, 2026, 07:08 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.