LWA-2026-0226 confirmed malware

@design-system-coopeuch/web@999.0.3

Malicious code in @design-system-coopeuch/web (npm)

Analysis

Preinstall hook executes cb.js, which collects system data including the output of the 'id' command and exfiltrates it via HTTP POST to attacker-controlled IP 157[.]173[.]126[.]113:8443/dep-confusion. Uses child_process.execSync and http.request to send the package name and system info to the external server. Dependency-confusion exfiltration pattern.

analyzed by
Leitwacht
first seen
May 27, 2026, 05:22 AM
analyzed
May 27, 2026, 05:22 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.