dms-backend@1.0.0
Malicious code in dms-backend (npm)
T1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The package dms-backend@1.0.0 contains a preinstall hook that runs automatically on npm install. It collects the hostname, current username, and working directory via $(hostname && whoami && pwd), then sends that data via HTTP POST to webhook[.]site/1ea0386f-dcc0-4f1b-bdbb-61732d6535fb/dms-backend — an attacker-controlled exfiltration endpoint. The package contains no legitimate code or functionality.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 09:50 AM
- analyzed
- Jun 15, 2026, 09:51 AM
Related advisories
- ts-webplug@3.0.5
- tsliverhome@1.1.5
- trgrip@1.0.4
- transform-es2015-destructuring@6.24.1
- texttweak-kit@1.0.0
- stylelint-standard@1.2.0
- sisubeny-bun-pwn-payload-1@1.0.0
- codyx-ai@1.14.42
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.