LWA-2026-11817 MAL-2026-15815 ↗ confirmed malware

cminhouse-api-gateway-nodejs@999.0.0

Malicious code in cminhouse-api-gateway-nodejs (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1552.004 · Private KeysT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web Service

Analysis

The postinstall hook runs index.js, a credential harvester. After a 5-15 second delay (skipping test/CI/container environments), it reads the victim's ~/.npmrc, .yarnrc, .git-credentials, SSH private keys, AWS credentials and SSO cache, GCP application-default credentials, Azure access tokens, kube config, docker config, terraform credentials, GitHub CLI hosts, netlify/supabase/firebase/vercel tokens, .pgpass, .my.cnf, .mongorc.js, vscode settings, gem/pypi/cargo credentials, and every environment variable whose name contains TOKEN/KEY/SECRET/PASSWORD/API/AUTH/CREDENTIAL/ACCESS or provider names (ANTHROPIC, OPENAI, AWS, AZURE, GCP, STRIPE, SLACK, DISCORD, etc.). The collected data is base64-encoded and exfiltrated to a Telegram bot at api[.]telegram[.]org (chat_id 8814152665) via sendMessage/sendDocument, and POSTed to hxxp://2[.]26[.]82[.]63:8888/collect.

analyzed by
Leitwacht
first seen
Sep 1, 2026, 04:41 PM
analyzed
Sep 1, 2026, 04:41 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.