LWA-2026-0225 confirmed malware
@design-system-coopeuch/web@999.0.2
Malicious code in @design-system-coopeuch/web (npm)
Analysis
Dependency-confusion package (version 999.0.2) with a preinstall hook 'node cb.js' that exfiltrates host reconnaissance to a remote C2. cb.js collects the hostname, install directory, output of 'id', 'uname -a', OS-release info, the current working directory, and the full list of environment-variable names, then POSTs this JSON to hxxp://157[.]173[.]126[.]113:8443/dep-confusion. C2/IOC: 157[.]173[.]126[.]113:8443, path /dep-confusion.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 05:22 AM
- analyzed
- May 27, 2026, 05:23 AM
Related advisories
- @design-system-coopeuch/web@999.0.3 same package
- @design-system-coopeuch/web@999.0.4 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.