@design-system-coopeuch/web@999.0.4
Malicious code in @design-system-coopeuch/web (npm)
Analysis
Dependency-confusion package (version 999.0.4) with a preinstall hook 'node cb.js'; the package also ships an identical cb-full.js. Both scripts gather host reconnaissance (hostname, install directory, output of 'id', 'uname -a', OS-release info, working directory, and all environment-variable names) and POST it as JSON to hxxp://157[.]173[.]126[.]113:8443/dep-confusion. C2/IOC: 157[.]173[.]126[.]113:8443, path /dep-confusion.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 05:22 AM
- analyzed
- May 27, 2026, 05:22 AM
Related advisories
- @design-system-coopeuch/web@999.0.2 same package
- @design-system-coopeuch/web@999.0.3 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.