LWA-2026-6346 confirmed malware

@digiptf/common@99.99.99

Malicious code in @digiptf/common (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1048 · Exfiltration Over Alternative Protocol

Analysis

@digiptf/common@99.99.99 is a dependency-confusion package with no functional code (index.js exports an empty object). Both the preinstall and install lifecycle hooks collect the installer's username, hostname, current working directory, and the package name, encode them as base64, and exfiltrate them via HTTP GET to hxxps://digiptf-common[.]callback[.]m0chan[.]co[.]uk/<base64-payload>. The hooks also perform a DNS lookup (nslookup) to a base64-encoded variant of the package name at the same domain (callback[.]m0chan[.]co[.]uk) as a secondary exfiltration channel.

analyzed by
Leitwacht
first seen
Jul 6, 2026, 11:37 AM
analyzed
Jul 6, 2026, 11:38 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.