LWA-2026-12724 confirmed malware

wie888r@99.0.1

Malicious code in wie888r (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

wie888r@99.0.1 is a dependency-confusion shim that beacons on install. Its package.json declares "postinstall": "node beacon.cjs", and beacon.cjs POSTs a JSON body containing the package name, the machine hostname, the install directory (__dirname), the current working directory, and the Node/npm version to hxxp://185[.]158[.]107[.]175:8787/_ah/dc with an x-beacon-package header. The package's index.js also calls the same beacon on require(), so simply importing the module name records the install even if the lifecycle hook is skipped. The package ships no real functionality: index.js exports a Proxy that returns no-op functions for every property access, so a build that imports it completes instead of crashing. The version number (99.0.1) and generic "Compatibility shim." description are chosen to win version resolution against the real dependency of the same name. The beacon is fire-and-forget over plaintext HTTP to a bare IP address, with a 5s timeout and errors swallowed. No credentials, tokens, environment variables, or files are read or transmitted. IOC: hxxp://185[.]158[.]107[.]175:8787/_ah/dc (POST, JSON body, x-beacon-package header).

analyzed by
Leitwacht
first seen
Oct 8, 2026, 07:18 PM
analyzed
Oct 8, 2026, 07:33 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.