real-router-utils@1.0.0
Malicious code in real-router-utils (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The package ships no code — only a package.json whose preinstall hook runs on install and sends the host's hostname, username, and current working directory to the webhook[.]site endpoint hxxps://webhook[.]site/e32d3b8a-a5df-40cc-ae60-7a8343b581e4 via an HTTP GET. This is an install-time host-recon beacon that exfiltrates system metadata to an external collection endpoint.
- analyzed by
- Leitwacht
- first seen
- Sep 2, 2026, 10:15 PM
- analyzed
- Sep 2, 2026, 10:16 PM
Related advisories
- @avigilon/node-webrtc@2.1.4
- tuxcmdfhjkw@1.0.0
- line-through@1.0.0
- order-package-saas@999.0.0
- bt2-api-gateway-node-js@999.0.0
- cminhouse-api-gateway-nodejs@999.0.0
- quartz-core@99.1.9
- @divineubg/divine@1.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.