LWA-2026-11930 MAL-2026-16032 ↗ confirmed malware

feishu-docx-mcp@0.3.2

Malicious code in feishu-docx-mcp (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

The preinstall hook of feishu-docx-mcp@0.3.2 runs `bun run index.js`, executing a 499KB obfuscated script at the package root (the legitimate package entry is dist/index.js). The obfuscated payload implements RC4 and AES-style encryption, injects a global function, and contains routines that validate GitHub access tokens and enumerate their scopes (repo, workflow) by sending `Authorization: token <token>` requests to a remote base URL. The install-time script makes outbound network connections during installation, consistent with credential harvesting and C2 beaconing.

analyzed by
Leitwacht
first seen
Sep 7, 2026, 09:27 AM
analyzed
Sep 7, 2026, 09:33 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.