nic-datagov@1.0.0
Malicious code in nic-datagov (npm)
T1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
This package contains a preinstall hook that runs on npm install. It collects the installer's hostname, username, and current working directory via hostname && whoami && pwd, then sends the data to webhook[.]site/1ea0386f-dcc0-4f1b-bdbb-61732d6535fb/nic-datagov over HTTP POST. webhook[.]site is a request-capture service commonly abused for data exfiltration. The package contains no functional code beyond this recon payload.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 09:50 AM
- analyzed
- Jun 15, 2026, 09:51 AM
Related advisories
- ts-enum-helper@1.0.0
- tether-base@99.0.0
- tecken@0.1.10
- electron-internal-utils@1.0.0
- skipthedishes_react@0.1.0
- server-up-ndot@1.0.0
- rtms-manager@1.2.0
- rtms-manager-dev@1.3.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.