LWA-2026-11758 confirmed malware
com.db.autobahn.notification-center-electron@88.88.1
Malicious code in com.db.autobahn.notification-center-electron (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The package's preinstall and postinstall hooks both run curl against hxxp://da9nfhavbsgte1dqq8fgrbb7fyfekc37i[.]cyowl[.]com/com[.]db[.]autobahn[.]notification-center-electron/ passing the installer's username (whoami), hostname, current working directory, and timestamp as query parameters. This exfiltrates host metadata to a remote server on every install. The package ships no functional code.
- analyzed by
- Leitwacht
- first seen
- Aug 30, 2026, 12:25 AM
- analyzed
- Aug 30, 2026, 12:25 AM
Related advisories
- test__123q1@2.1.3
- claude-channel-telegram@9.9.9
- claude-channel-discord@9.9.9
- grafeno-payments@1.0.0
- grafeno-webhook@1.0.0
- grafeno-billing@1.0.0
- spc_login@1.0.0
- spc-grafeno-login@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.