LWA-2026-0204 MAL-2026-2446 ↗ confirmed malware

@corpweb-ui/wmkt-library@99.99.12

Malicious code in @corpweb-ui/wmkt-library (npm)

T1071.001 · Web Protocols

Analysis

On installation the package's preinstall hook runs index.js, which executes system reconnaissance commands (whoami, hostname, uname -a, and curl to ifconfig[.]me to learn the public IP), formats the output as a fake "VERISIGN - DEEP RCE CONFIRMED" banner, and exfiltrates the data to a Telegram bot (hxxps://api[.]telegram[.]org) using a hardcoded bot token and chat_id 1483949647. Code comments describe the attack intent.

analyzed by
Leitwacht
first seen
May 27, 2026, 03:34 AM
analyzed
May 27, 2026, 04:05 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.