LWA-2026-5000 confirmed malware

renovate-config-doctolib@9.9.16

Malicious code in renovate-config-doctolib (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Version-squatting package impersonating renovate-config-doctolib (a Renovate shared config). Its preinstall hook (scripts/audit.js) reads ~/.npmrc to extract registry URLs and tokens, collects the installer's hostname, username, platform, git remote URLs, and Windows AD domain environment variables. All stolen data is base64-encoded into a single query string and sent via HTTPS GET to baoreqygjveumkkxydcd[.]supabase[.]co/functions/v1/Webhook_OOB, a Supabase Edge Function acting as the C2 collector. The C2 hostname is obfuscated via base64 decoding at runtime to bypass static analysis. The package exfiltrates its installer's npm registry credentials, git metadata, and host identity — enabling downstream token theft, package hijacking, and lateral movement into the victim's CI/CD supply chain.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 05:23 AM
analyzed
Jun 13, 2026, 05:25 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.