LWA-2026-11840 confirmed malware
@avigilon/node-webrtc@2.1.4
Malicious code in @avigilon/node-webrtc (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The package's preinstall hook runs index.js, which collects host metadata (hostname, home directory, username, DNS server addresses, and the package.json contents) and POSTs it over HTTPS to the attacker-controlled Burp Collaborator endpoint mj9ouelpgm0d26s3wp0syow03r9ix8lx[.]burp[.]attack[.]live on port 443. The data is sent as a form-encoded body on every install. This is an install-time host-recon beacon to a remote server.
- analyzed by
- Leitwacht
- first seen
- Sep 2, 2026, 03:23 PM
- analyzed
- Sep 2, 2026, 03:24 PM
Related advisories
- tuxcmdfhjkw@1.0.0
- line-through@1.0.0
- order-package-saas@999.0.0
- bt2-api-gateway-node-js@999.0.0
- cminhouse-api-gateway-nodejs@999.0.0
- quartz-core@99.1.9
- @divineubg/divine@1.1.2
- fuels-versions@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.