LWA-2026-5540 confirmed malware
xz-c-d@1.5.3
Malicious code in xz-c-d (npm)
T1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
A heavily obfuscated ES module that collects the browser's user-agent string (navigator.userAgent) and exfiltrates it as a base64-encoded JSON payload inside an X-Access HTTP header, POSTed to a remote C2 endpoint whose URL is obfuscated and decoded at runtime. The module first attempts to send the payload via navigator.sendBeacon() (stealthy exfiltration that persists after page unload), falling back to an axios HTTP POST. The package has no declared purpose (empty description, no repository) and is published from a throwaway identity.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 08:08 AM
- analyzed
- Jun 16, 2026, 08:10 AM
Related advisories
- xpna-context@1.0.2
- xmr-btc-lib-js@1.2.1
- uidai_reusable_components@0.4.2
- xboxauthwrapper@3.9.8
- work-planner-client@1.0.0
- workbox-stable-xyz@1.0.0
- wisdomtreetest@1.0.1
- wime-zle@1.1.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.