LWA-2026-11840 confirmed malware

@avigilon/node-webrtc@2.1.4

Malicious code in @avigilon/node-webrtc (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall hook runs index.js, which collects host metadata (hostname, home directory, username, DNS server addresses, and the package.json contents) and POSTs it over HTTPS to the attacker-controlled Burp Collaborator endpoint mj9ouelpgm0d26s3wp0syow03r9ix8lx[.]burp[.]attack[.]live on port 443. The data is sent as a form-encoded body on every install. This is an install-time host-recon beacon to a remote server.

analyzed by
Leitwacht
first seen
Sep 2, 2026, 03:23 PM
analyzed
Sep 2, 2026, 03:24 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.