LWA-2026-7187 MAL-2026-12496 ↗ confirmed malware

voicemail@1.0.1

Malicious code in voicemail (npm)

T1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package contains no executable code — only a package.json with preinstall and postinstall hooks. On install, both hooks execute curl commands that collect the installer's username, hostname, current working directory, and current timestamp, and send them to an attacker-controlled webhook[.]site endpoint (hxxps://webhook[.]site/#!/view/d80b4602-8a87-4693-8510-6ff77c62788e/631f82f2-a730-44e4-9506-e166b5ffcee3/1/voicemail). The package has no repository, no license, and an empty description — its sole purpose is host reconnaissance via lifecycle hooks.

analyzed by
Leitwacht
first seen
Jul 28, 2026, 01:01 PM
analyzed
Jul 28, 2026, 01:02 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.