LWA-2026-0203 MAL-2026-2446 ↗ confirmed malware

@corpweb-ui/wmkt-library@99.99.11

Malicious code in @corpweb-ui/wmkt-library (npm)

T1071.001 · Web Protocols

Analysis

True positive supply-chain attack. Package @corpweb-ui/wmkt-library@99.99.11 contains a preinstall hook that executes system commands (id, pwd, hostname) via child_process.exec and exfiltrates the output to a Telegram bot (token [redacted-credential], chatId 1483949647). The code explicitly states "RCE CONFIRMED" and targets the package itself. Publisher email [account] is a throwaway account. Version 99.99.11 suggests typosquatting/impersonation. This is a clear data exfiltration attack via npm lifecycle hook.

analyzed by
Leitwacht
first seen
May 27, 2026, 03:34 AM
analyzed
May 27, 2026, 04:05 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.