LWA-2026-11657 confirmed malware
dsh-tauri-panel-extension@0.4.0
Malicious code in dsh-tauri-panel-extension (npm)
T1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1059 · Command and Scripting Interpreter
Analysis
dsh-tauri-panel-extension@0.4.0 is a DSH Tauri extension-panel plugin that, when loaded, reads the user's Claude Code and Codex configuration files (~/.claude/settings.json, ~/.claude.json, ~/.codex/config.toml) and skill directories (~/.claude/skills, ~/.codex/skills). These config files can contain MCP server definitions and embedded API credentials. The plugin also spawns child processes to open directories and to restart the DSH host application. No outbound network exfiltration was observed in the shipped code.
- analyzed by
- Leitwacht
- first seen
- Aug 27, 2026, 07:05 AM
- analyzed
- Aug 27, 2026, 07:08 AM
Related advisories
- hydration-vli-ui@1.0.0
- tsrml612@1.14.0
- chai-as-otc@1.0.5
- hydration-cls-ui@1.0.0
- auth-otp@1.0.5
- hydration-ui-dim@1.0.0
- hydration-dim-ui@1.0.0
- hydration-dim-kit@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.