LWA-2026-5517 confirmed malware
workbox-stable-xyz@1.0.0
Malicious code in workbox-stable-xyz (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
workbox-stable-xyz@1.0.0 is a combosquat package impersonating Google's workbox library. On installation the preinstall script (node index.js) collects system information — hostname, home directory path, current username, DNS server addresses, and the installer's working directory — and POSTs the data as a URL-encoded HTTPS request to eo1jookr73gehju[.]m[.]pipedream[.]net. The destination is a Pipedream webhook endpoint, a common C2/exfiltration service. The collected metadata can be used to fingerprint the victim environment for follow-on targeting.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 04:58 AM
- analyzed
- Jun 16, 2026, 05:00 AM
Related advisories
- wisdomtreetest@1.0.1
- wime-zle@1.1.4
- web-pool@2.3.5
- check-ulid@3.0.2
- web3-deploy-helper@1.0.0
- walletconnectionjs@1.1.1
- vue-template-compiler-plugin@2.7.16
- vl-ui-code-preview@10.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.