@corpweb-ui/wmkt-library@99.99.12
Malicious code in @corpweb-ui/wmkt-library (npm)
T1071.001 · Web Protocols
Analysis
On installation the package's preinstall hook runs index.js, which executes system reconnaissance commands (whoami, hostname, uname -a, and curl to ifconfig[.]me to learn the public IP), formats the output as a fake "VERISIGN - DEEP RCE CONFIRMED" banner, and exfiltrates the data to a Telegram bot (hxxps://api[.]telegram[.]org) using a hardcoded bot token and chat_id 1483949647. Code comments describe the attack intent.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 03:34 AM
- analyzed
- May 27, 2026, 04:05 AM
Related advisories
- @corpweb-ui/wmkt-library@99.99.11 same package
- css-flow-render-shim@1.0.0
- wix-ssr-thunderbolt-grid-polyfill@0.1.0
- css-reading-display-polyfill@1.0.0
- dotenv-runtime@1.0.0
- hardhat-promised@2.21.0
- css-jptvix-polyfill@1.0.0
- tailwind-forms-kit@0.5.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.