LWA-2026-5517 confirmed malware

workbox-stable-xyz@1.0.0

Malicious code in workbox-stable-xyz (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

workbox-stable-xyz@1.0.0 is a combosquat package impersonating Google's workbox library. On installation the preinstall script (node index.js) collects system information — hostname, home directory path, current username, DNS server addresses, and the installer's working directory — and POSTs the data as a URL-encoded HTTPS request to eo1jookr73gehju[.]m[.]pipedream[.]net. The destination is a Pipedream webhook endpoint, a common C2/exfiltration service. The collected metadata can be used to fingerprint the victim environment for follow-on targeting.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 04:58 AM
analyzed
Jun 16, 2026, 05:00 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.