LWA-2026-0225 confirmed malware

@design-system-coopeuch/web@999.0.2

Malicious code in @design-system-coopeuch/web (npm)

Analysis

Dependency-confusion package (version 999.0.2) with a preinstall hook 'node cb.js' that exfiltrates host reconnaissance to a remote C2. cb.js collects the hostname, install directory, output of 'id', 'uname -a', OS-release info, the current working directory, and the full list of environment-variable names, then POSTs this JSON to hxxp://157[.]173[.]126[.]113:8443/dep-confusion. C2/IOC: 157[.]173[.]126[.]113:8443, path /dep-confusion.

analyzed by
Leitwacht
first seen
May 27, 2026, 05:22 AM
analyzed
May 27, 2026, 05:23 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.