LWA-2026-11715 confirmed malware

claude-channel-discord@9.9.9

Malicious code in claude-channel-discord (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

The preinstall and postinstall hooks both execute index.js, which reads the machine hostname via os.hostname() and POSTs it to the webhook collector hxxps://eo8f3m3ho26a0nm[.]m[.]pipedream[.]net/claude-channel-discord?h=<hostname> on every install. The package is a 662-byte stub whose only behaviour is this hostname beacon to a remote endpoint.

analyzed by
Leitwacht
first seen
Aug 29, 2026, 07:28 AM
analyzed
Aug 29, 2026, 07:29 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.