LWA-2026-6599 MAL-2026-10129 ↗ confirmed malware

rtc-integration-frontend-sdk@99.9.0

Malicious code in rtc-integration-frontend-sdk (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

On install, the postinstall hook (node index.js) executes a host-reconnaissance script. It collects the system's hostname, OS platform and architecture, username, private IP addresses, public IP (queried from api[.]ipify[.]org), current working directory, and package name, then exfiltrates all of this data to a hardcoded Discord webhook URL (discord[.]com/api/webhooks/1524917003394089029/...). The webhook URL is the C2 endpoint for data exfiltration.

analyzed by
Leitwacht
first seen
Jul 10, 2026, 02:53 PM
analyzed
Jul 10, 2026, 02:53 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.