LWA-2026-5718 MAL-2026-10874 ↗ confirmed malware

@dxcl/fund-js@99.99.99

Malicious code in @dxcl/fund-js (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1071.004 · DNST1041 · Exfiltration Over C2 Channel

Analysis

@dxcl/fund-js@99.99.99 is a dependency-confusion package that deploys host reconnaissance and data exfiltration via lifecycle hooks. The preinstall and install scripts collect the installer's username, hostname, current working directory, and package name, base64-encode the combined data, and exfiltrate it to the attacker-controlled domain callback[.]m0chan[.]co[.]uk via both an HTTP POST (curl) and a DNS query (nslookup). The actual JavaScript code shipped with the package is an empty stub (module.exports = {}); the entire malicious behaviour runs during installation.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 11:37 AM
analyzed
Jun 18, 2026, 11:37 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.