LWA-2026-12294 MAL-2026-16306 ↗ confirmed malware

@nimbusedge2/xa@1.1.0

Malicious code in @nimbusedge2/xa (npm)

T1059.004 · Unix ShellT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel

Analysis

The preinstall hook of @nimbusedge2/xa@1.1.0 opens a reverse shell to 147[.]93[.]157[.]202[.]nip[.]io on port 8080 and pipes the interactive session to an exfiltration endpoint at hxxp://canarytokens[.]com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact[.]php. Installing the package gives the remote host an interactive bash shell on the victim machine and forwards the session's output to the canarytokens URL. The package ships no other code (package.json only).

analyzed by
Leitwacht
first seen
Sep 21, 2026, 01:33 AM
analyzed
Sep 21, 2026, 01:33 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.