LWA-2026-7186 MAL-2026-11159 ↗ confirmed malware

toll_free@1.0.1

Malicious code in toll_free (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

toll_free@1.0.1 contains no executable code — only a package.json with preinstall and postinstall hooks that curl a webhook[.]site URL, exfiltrating the installer's username (whoami), hostname, current working directory, and a timestamp. The curl output is discarded and errors suppressed, confirming the sole purpose is reconnaissance and beaconing, not installation. The exfiltration target is webhook[.]site (a webhook testing service commonly abused by malware for C2 callback collection).

analyzed by
Leitwacht
first seen
Jul 28, 2026, 01:00 PM
analyzed
Jul 28, 2026, 01:00 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.