google-caja-bower@20.20.20
Malicious code in google-caja-bower (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 Channel
Analysis
Combosquat package impersonating Google Caja. The preinstall hook (node index.js) collects system information — hostname, username, UID/GID, platform, OS release, home directory — runs id/whoami/hostname/systeminfo commands, reads /etc/passwd and other sensitive files, and exfiltrates all collected data to a Discord webhook (discord[.]com/api/webhooks/1471187072869073017/4TsUJVIxwZ_K73DBPmHOX4CDMq7TYdt1nTkg3KSCjA2L76gazQfO_mODyZfxPMuikqur) via HTTPS POST with an @everyone ping.
- analyzed by
- Leitwacht
- first seen
- Jul 11, 2026, 04:10 PM
- analyzed
- Jul 11, 2026, 04:10 PM
Related advisories
- @wagni_bot/meteora-sdk@1.2.0
- @wagni_bot/ethereum-wallet@1.0.0
- @wagni_bot/solana-sdk@1.0.0
- @wagni_bot/orca-sdk@1.0.0
- ts-eslint-jest@1.0.0
- jest-formatter@1.0.0
- zredis-typed@1.0.127
- zod-pino434@1.0.127
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.