LWA-2026-11843 MAL-2026-15825 ↗ confirmed malware

real-router-utils@1.0.0

Malicious code in real-router-utils (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

The package ships no code — only a package.json whose preinstall hook runs on install and sends the host's hostname, username, and current working directory to the webhook[.]site endpoint hxxps://webhook[.]site/e32d3b8a-a5df-40cc-ae60-7a8343b581e4 via an HTTP GET. This is an install-time host-recon beacon that exfiltrates system metadata to an external collection endpoint.

analyzed by
Leitwacht
first seen
Sep 2, 2026, 10:15 PM
analyzed
Sep 2, 2026, 10:16 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.