LWA-2026-11979 MAL-2026-16117 ↗ confirmed malware

etoro-cashout@999.0.0

Malicious code in etoro-cashout (npm)

T1195.002 · Compromise Software Supply ChainT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The preinstall hook (node preinstall.js) sends an HTTP GET to hxxp://209[.]126[.]81[.]147/etoro-depconf-poce346552f776f/npm/{hostname}/{username}/{cwd}, exfiltrating the machine's hostname, OS username, and current working directory to a hardcoded remote IP on install. The package is a 3-file stub published at version 999.0.0 under a name resembling a financial service, with no functional code (index.js is 21 bytes).

analyzed by
Leitwacht
first seen
Sep 10, 2026, 04:02 AM
analyzed
Sep 10, 2026, 04:04 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.