LWA-2026-5355 MAL-2026-5836 ↗ confirmed malware

nic-datagov@1.0.0

Malicious code in nic-datagov (npm)

T1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

This package contains a preinstall hook that runs on npm install. It collects the installer's hostname, username, and current working directory via hostname && whoami && pwd, then sends the data to webhook[.]site/1ea0386f-dcc0-4f1b-bdbb-61732d6535fb/nic-datagov over HTTP POST. webhook[.]site is a request-capture service commonly abused for data exfiltration. The package contains no functional code beyond this recon payload.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 09:50 AM
analyzed
Jun 15, 2026, 09:51 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.