LWA-2026-11863 MAL-2026-15847 ↗ confirmed malware

fieldbase-webapplication-buildtools@99.99.99

Malicious code in fieldbase-webapplication-buildtools (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The package's preinstall and install hooks run on installation. They base64-encode the current username, hostname, working directory, and package name, then POST that data to hxxps://eoy34oyrep9j5x8[.]m[.]pipedream[.]net/<encoded-data> via curl. The hooks also perform a DNS lookup exfiltration channel by base64-encoding the package name and resolving it as a subdomain of eoy34oyrep9j5x8[.]m[.]pipedream[.]net via nslookup. The package ships an empty index.js; all behaviour is in the install lifecycle scripts.

analyzed by
Leitwacht
first seen
Sep 3, 2026, 02:15 PM
analyzed
Sep 3, 2026, 02:16 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.