LWA-2026-12365 MAL-2026-16478 ↗ confirmed malware

event-hunter@1.0.0

Malicious code in event-hunter (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

The package declares itself a dependency-confusion RCE artifact. Its postinstall hook runs index.js, which collects the host's hostname and install timestamp and sends them base64-encoded to the remote endpoint hxxps://estimator-nemeses-unwatched[.]ngrok-free[.]dev/canary on every install, exfiltrating host metadata to an attacker-controlled tunnel.

analyzed by
Leitwacht
first seen
Sep 23, 2026, 10:27 AM
analyzed
Sep 23, 2026, 10:28 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.