LWA-2026-6617 MAL-2026-10186 ↗ confirmed malware

google-caja-bower@20.20.20

Malicious code in google-caja-bower (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 Channel

Analysis

Combosquat package impersonating Google Caja. The preinstall hook (node index.js) collects system information — hostname, username, UID/GID, platform, OS release, home directory — runs id/whoami/hostname/systeminfo commands, reads /etc/passwd and other sensitive files, and exfiltrates all collected data to a Discord webhook (discord[.]com/api/webhooks/1471187072869073017/4TsUJVIxwZ_K73DBPmHOX4CDMq7TYdt1nTkg3KSCjA2L76gazQfO_mODyZfxPMuikqur) via HTTPS POST with an @everyone ping.

analyzed by
Leitwacht
first seen
Jul 11, 2026, 04:10 PM
analyzed
Jul 11, 2026, 04:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.