LWA-2026-12210 MAL-2026-16271 ↗ confirmed malware

test89078-auth@99.99.99

Malicious code in test89078-auth (npm)

T1082 · System Information DiscoveryT1071.004 · DNST1041 · Exfiltration Over C2 Channel

Analysis

The preinstall hook (node index.js) collects the machine hostname and the current username via os.hostname() and os.userInfo().username, concatenates them, and exfiltrates them through a DNS lookup to a subdomain of the attacker-controlled domain dnshook[.]site (31ee29fe-db68-4fd3-86a2-2b707b9e95f0[.]dnshook[.]site). The DNS query encodes the host identity data in the subdomain label, silently beaconing the victim's machine identity to the remote server on every install.

analyzed by
Leitwacht
first seen
Sep 17, 2026, 03:06 PM
analyzed
Sep 17, 2026, 03:07 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.