LWA-2026-5713 MAL-2026-10872 ↗ confirmed malware

@dxcl/account-js@99.99.99

Malicious code in @dxcl/account-js (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1048 · Exfiltration Over Alternative Protocol

Analysis

The package @dxcl/account-js at version 99.99.99 is a dependency-confusion stub with no functional code (index.js exports an empty object). Its preinstall and install hooks collect system identity (whoami, hostname, current working directory) and exfiltrate it via HTTP GET and DNS query to callback[.]m0chan[.]co[.]uk. The script builds two exfiltration channels: an HTTPS request to hxxps://<base64-package-name>.callback[.]m0chan[.]co[.]uk/<base64-of-whoami:hostname:pwd:package_name>, and a DNS nslookup to <base64-package-name>.<slug-package-name>.callback[.]m0chan[.]co[.]uk. The C2 host is callback[.]m0chan[.]co[.]uk.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 11:21 AM
analyzed
Jun 18, 2026, 11:22 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.