@corpweb-ui/wmkt-library@99.99.11
Malicious code in @corpweb-ui/wmkt-library (npm)
T1071.001 · Web Protocols
Analysis
True positive supply-chain attack. Package @corpweb-ui/wmkt-library@99.99.11 contains a preinstall hook that executes system commands (id, pwd, hostname) via child_process.exec and exfiltrates the output to a Telegram bot (token [redacted-credential], chatId 1483949647). The code explicitly states "RCE CONFIRMED" and targets the package itself. Publisher email [account] is a throwaway account. Version 99.99.11 suggests typosquatting/impersonation. This is a clear data exfiltration attack via npm lifecycle hook.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 03:34 AM
- analyzed
- May 27, 2026, 04:05 AM
Related advisories
- @corpweb-ui/wmkt-library@99.99.12 same package
- specials-resources-server@35.8.1
- @kolbo/mcp@1.57.1
- sme-rko-finance-front-operations-penalty@35.8.1
- sme-rko-finance-front-operations-overnight@35.8.1
- sme-rko-finance-front-operations-pegasus@35.8.1
- sme-rko-finance-front-operations-fee@35.8.1
- sme-rko-finance-front-operations-domain@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.