LWA-2026-5648 MAL-2026-6065 ↗ confirmed malware

lab-services@99.0.0

Malicious code in lab-services (npm)

Analysis

This package is a dependency-confusion squat (published at version 99.0.0 to outrank an internal package of the same name). Its package.json declares a preinstall hook that executes a bundled script on install. The script fetches the machine public IP from an external IP-echo service, then gathers host reconnaissance (hostname, public IP, current working directory, OS platform, CPU architecture and a timestamp) and POSTs that data as a JSON message to a hardcoded Discord webhook before exiting. Installing the package silently leaks identifying environment details to an attacker-controlled endpoint.

analyzed by
Leitwacht
first seen
Jun 17, 2026, 04:13 PM
analyzed
Jun 17, 2026, 04:21 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.