autobahn-electron-probe@99.99.1
Malicious code in autobahn-electron-probe (npm)
Analysis
autobahn-electron-probe@99.99.1 is a dependency-confusion stub (high version 99.99.1 on a name resembling an internal package) shipping a 618-byte tarball. Both its preinstall and postinstall hooks execute curl against hxxp://da9nu7avbsgtvoua4om0746ibn3suot7h[.]cyowl[.]com/autobahn-electron-probe/ with query parameters exfiltrating the installer's username ($(whoami)), hostname ($(hostname)), current working directory ($PWD), and a timestamp, discarding the response to /dev/null. Installing the package beacons this host metadata to the remote host on every install.
- analyzed by
- Leitwacht
- first seen
- Aug 30, 2026, 01:15 AM
- analyzed
- Aug 30, 2026, 01:16 AM
Related advisories
- com.db.autobahn.notification-center-electron@88.88.1
- node-request-utils@1.0.0
- cbc97b7a@1.1787999998.0
- test__123q1@2.1.3
- claude-channel-telegram@9.9.9
- claude-channel-discord@9.9.9
- grafeno-payments@1.0.0
- grafeno-webhook@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.