LWA-2026-6095 MAL-2026-6596 ↗ confirmed malware

@digitalcnzz/embedded-sdk@1.0.7

Malicious code in @digitalcnzz/embedded-sdk (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1480 · Execution GuardrailsT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package @digitalcnzz/embedded-sdk@1.0.7 is a trojanized clone of the Apache Superset embedded SDK. On postinstall (node .prepare.cjs), it first evades analysis by exiting if it detects sandbox environments (checking for dummy/honey tokens, CI/CD variables, sandbox hostnames/usernames, detector env vars). After passing these evasion checks and a 15-45 second randomized delay, it collects system fingerprint data (hostname, username, platform, architecture, Node version, non-internal IP addresses, registry URL) and dumps ALL environment variables (excluding only npm_lifecycle_* variables). This captured data — including NPM_TOKEN, GITHUB_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, and any other secrets present in the environment — is POSTed as JSON to open[.]larksuite[.]com (Lark/Feishu) via a bot webhook endpoint at /open-api/bot/v2/hook/{webhook-id}. The package has no repository, no README, and the only functional file is the malicious postinstall hook.

analyzed by
Leitwacht
first seen
Jun 28, 2026, 09:02 PM
analyzed
Jun 28, 2026, 09:09 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.