LWA-2026-12748 MAL-2026-17708 ↗ confirmed malware

xblaxw@1.0.1

Malicious code in xblaxw (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

xblaxw@1.0.1 is a "compatibility shim" package whose postinstall hook ("node beacon.cjs") beacons host metadata to a hardcoded IP address. beacon.cjs POSTs a JSON body containing the package name, hostname, install path, working directory and npm/node version to hxxp://185[.]158[.]107[.]175:8787/_ah/dc with an X-Beacon-Package: xblaxw header. index.js re-fires the same beacon whenever the package is required and exports a Proxy that returns no-op functions for any property access, so a project that merely imports the name silently triggers the callback without breaking the build. The package name is a combosquat-style shim intended to be pulled in as a dependency; the beacon endpoint is a bare IP with no legitimate service behind it. No credential, token or file contents are read or sent — the payload is limited to install/host fingerprinting reported to the remote endpoint.

analyzed by
Leitwacht
first seen
Oct 8, 2026, 08:46 PM
analyzed
Oct 8, 2026, 10:03 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.