LWA-2026-12086 MAL-2026-16145 ↗ confirmed malware

concierge-sdk@99.99.99

Malicious code in concierge-sdk (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The postinstall hook runs exfil.js, which collects the full environment (all environment variables, working directory, platform, Node version, and username) and POSTs them as JSON to hxxps://webhook[.]site/4f4566fc-e72f-415b-818f-fdb42dc9891d. This exfiltrates any credentials or tokens present in the installer's environment (e.g. npm/GitHub/cloud tokens) at install time. The package otherwise ships only a stub client class and a synthetic version number.

analyzed by
Leitwacht
first seen
Sep 13, 2026, 02:18 PM
analyzed
Sep 13, 2026, 02:20 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.