LWA-2026-12743 MAL-2026-17708 ↗ confirmed malware

xblaxw@1.1.0

Malicious code in xblaxw (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

xblaxw@1.1.0 ships a postinstall hook ("node beacon.cjs") that runs automatically on npm install with no opt-in. beacon.cjs collects machine and install metadata — the host hostname, the package install path (__dirname), the current working directory, and the npm/node user-agent string — and POSTs it as JSON to the hardcoded endpoint hxxp://185[.]158[.]107[.]175:8787/_ah/dc with the header X-Beacon-Package: xblaxw. The request is sent over plain HTTP to a raw IP address, is retried, and network errors are silently swallowed so the install appears to succeed. The package's stated purpose ("Compatibility shim.") requires no network activity, and the beacon's own comment claims it reports "only machine/package metadata" while providing no repository or research provenance. This is an install-time host-fingerprinting beacon phoning home to a hardcoded C2 address.

analyzed by
Leitwacht
first seen
Oct 8, 2026, 08:46 PM
analyzed
Oct 8, 2026, 09:17 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.