LWA-2026-11716 MAL-2026-15624 ↗ confirmed malware

claude-channel-telegram@9.9.9

Malicious code in claude-channel-telegram (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

The package runs a preinstall and postinstall hook that executes index.js, which reads the machine hostname and POSTs it to a remote webhook at eo8f3m3ho26a0nm[.]m[.]pipedream[.]net (path /claude-channel-telegram?h=<hostname>). The install-time beacon exfiltrates the hostname to an external webhook host on every install.

analyzed by
Leitwacht
first seen
Aug 29, 2026, 07:29 AM
analyzed
Aug 29, 2026, 07:29 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.