@corpweb-ui/wmkt-library@99.99.12
Malicious code in @corpweb-ui/wmkt-library (npm)
T1071.001 · Web Protocols
Analysis
On installation the package's preinstall hook runs index.js, which executes system reconnaissance commands (whoami, hostname, uname -a, and curl to ifconfig[.]me to learn the public IP), formats the output as a fake "VERISIGN - DEEP RCE CONFIRMED" banner, and exfiltrates the data to a Telegram bot (hxxps://api[.]telegram[.]org) using a hardcoded bot token and chat_id 1483949647. Code comments describe the attack intent.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 03:34 AM
- analyzed
- May 27, 2026, 04:05 AM
Related advisories
- @corpweb-ui/wmkt-library@99.99.11 same package
- specials-resources-server@35.8.1
- @kolbo/mcp@1.57.1
- sme-rko-finance-front-operations-penalty@35.8.1
- sme-rko-finance-front-operations-overnight@35.8.1
- sme-rko-finance-front-operations-pegasus@35.8.1
- sme-rko-finance-front-operations-fee@35.8.1
- sme-rko-finance-front-operations-domain@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.