@corpweb-ui/wmkt-library@99.99.11
Malicious code in @corpweb-ui/wmkt-library (npm)
T1071.001 · Web Protocols
Analysis
True positive supply-chain attack. Package @corpweb-ui/wmkt-library@99.99.11 contains a preinstall hook that executes system commands (id, pwd, hostname) via child_process.exec and exfiltrates the output to a Telegram bot (token [redacted-credential], chatId 1483949647). The code explicitly states "RCE CONFIRMED" and targets the package itself. Publisher email [account] is a throwaway account. Version 99.99.11 suggests typosquatting/impersonation. This is a clear data exfiltration attack via npm lifecycle hook.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 03:34 AM
- analyzed
- May 27, 2026, 04:05 AM
Related advisories
- @corpweb-ui/wmkt-library@99.99.12 same package
- css-flow-render-shim@1.0.0
- wix-ssr-thunderbolt-grid-polyfill@0.1.0
- css-reading-display-polyfill@1.0.0
- dotenv-runtime@1.0.0
- hardhat-promised@2.21.0
- css-jptvix-polyfill@1.0.0
- tailwind-forms-kit@0.5.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.