LWA-2026-10629 MAL-2026-13435 ↗ confirmed malware

@united-airlines-org/atmos-design-system@40.0.0

Malicious code in @united-airlines-org/atmos-design-system (npm)

T1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall hook runs curl against the attacker-controlled host bxss[.]boll-sec[.]de, appending the machine's hostname base64-encoded as a URL path segment (hostname_<base64>). On every install it exfiltrates the hostname of the installing machine to this remote host. The package ships no code, README, or license — only the malicious install hook.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 03:23 PM
analyzed
Aug 6, 2026, 03:24 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.