LWA-2026-5719 MAL-2026-10875 ↗ confirmed malware

@dxcl/http-common-js@99.99.99

Malicious code in @dxcl/http-common-js (npm)

T1059.004 · Unix ShellT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1071.004 · DNST1041 · Exfiltration Over C2 Channel

Analysis

Package @dxcl/http-common-js@99.99.99 contains identical malicious preinstall and install lifecycle hooks. On installation, both hooks collect the installer's username, hostname, current working directory, and the package name itself — all base64-encoded and exfiltrated via HTTPS GET to callback[.]m0chan[.]co[.]uk using curl. A secondary DNS lookup (nslookup) against the same domain is also performed, serving as a DNS-based beacon/exfiltration channel. The package's index.js is an empty stub (module.exports = {}), and its description is a generic decoy ('Internal automation library.'). The package has no legitimate functionality — its sole purpose is host reconnaissance and outbound beaconing.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 11:37 AM
analyzed
Jun 18, 2026, 11:37 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.