LWA-2026-0226 confirmed malware
@design-system-coopeuch/web@999.0.3
Malicious code in @design-system-coopeuch/web (npm)
Analysis
Preinstall hook executes cb.js, which collects system data including the output of the 'id' command and exfiltrates it via HTTP POST to attacker-controlled IP 157[.]173[.]126[.]113:8443/dep-confusion. Uses child_process.execSync and http.request to send the package name and system info to the external server. Dependency-confusion exfiltration pattern.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 05:22 AM
- analyzed
- May 27, 2026, 05:22 AM
Related advisories
- @design-system-coopeuch/web@999.0.2 same package
- @design-system-coopeuch/web@999.0.4 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.