LWA-2026-11715 confirmed malware
claude-channel-discord@9.9.9
Malicious code in claude-channel-discord (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The preinstall and postinstall hooks both execute index.js, which reads the machine hostname via os.hostname() and POSTs it to the webhook collector hxxps://eo8f3m3ho26a0nm[.]m[.]pipedream[.]net/claude-channel-discord?h=<hostname> on every install. The package is a 662-byte stub whose only behaviour is this hostname beacon to a remote endpoint.
- analyzed by
- Leitwacht
- first seen
- Aug 29, 2026, 07:28 AM
- analyzed
- Aug 29, 2026, 07:29 AM
Related advisories
- grafeno-payments@1.0.0
- grafeno-webhook@1.0.0
- grafeno-billing@1.0.0
- spc_login@1.0.0
- spc-grafeno-login@1.0.0
- grafeno-products-wrapper@999.0.0
- grafeno-products@999.0.0
- grafeno-actions@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.