LWA-2026-5353 MAL-2026-5826 ↗ confirmed malware

dms-backend@1.0.0

Malicious code in dms-backend (npm)

T1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

The package dms-backend@1.0.0 contains a preinstall hook that runs automatically on npm install. It collects the hostname, current username, and working directory via $(hostname && whoami && pwd), then sends that data via HTTP POST to webhook[.]site/1ea0386f-dcc0-4f1b-bdbb-61732d6535fb/dms-backend — an attacker-controlled exfiltration endpoint. The package contains no legitimate code or functionality.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 09:50 AM
analyzed
Jun 15, 2026, 09:51 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.