LWA-2026-6806 MAL-2026-10675 ↗ confirmed malware

ac-raf-emitter@3.0.1

Malicious code in ac-raf-emitter (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

Package declares itself a supply chain attack vector. On npm install, the preinstall hook executes curl to POST the hostname and current timestamp to webhook[.]site/54919426-084d-4288-8f80-e36ae5c76e32 — exfiltrating system identity and install time to an external webhook endpoint. The tarball contains only a package.json with no functional code.

analyzed by
Leitwacht
first seen
Jul 15, 2026, 10:18 AM
analyzed
Jul 15, 2026, 10:18 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.