claude-channel-telegram@9.9.9
Malicious code in claude-channel-telegram (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The package runs a preinstall and postinstall hook that executes index.js, which reads the machine hostname and POSTs it to a remote webhook at eo8f3m3ho26a0nm[.]m[.]pipedream[.]net (path /claude-channel-telegram?h=<hostname>). The install-time beacon exfiltrates the hostname to an external webhook host on every install.
- analyzed by
- Leitwacht
- first seen
- Aug 29, 2026, 07:29 AM
- analyzed
- Aug 29, 2026, 07:29 AM
Related advisories
- claude-channel-discord@9.9.9
- grafeno-payments@1.0.0
- grafeno-webhook@1.0.0
- grafeno-billing@1.0.0
- spc_login@1.0.0
- spc-grafeno-login@1.0.0
- grafeno-products-wrapper@999.0.0
- grafeno-products@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.