LWA-2026-11759 MAL-2026-15589 ↗ confirmed malware

autobahn-electron-probe@99.99.1

Malicious code in autobahn-electron-probe (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

autobahn-electron-probe@99.99.1 is a dependency-confusion stub (high version 99.99.1 on a name resembling an internal package) shipping a 618-byte tarball. Both its preinstall and postinstall hooks execute curl against hxxp://da9nu7avbsgtvoua4om0746ibn3suot7h[.]cyowl[.]com/autobahn-electron-probe/ with query parameters exfiltrating the installer's username ($(whoami)), hostname ($(hostname)), current working directory ($PWD), and a timestamp, discarding the response to /dev/null. Installing the package beacons this host metadata to the remote host on every install.

analyzed by
Leitwacht
first seen
Aug 30, 2026, 01:15 AM
analyzed
Aug 30, 2026, 01:16 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.