@united-airlines-org/atmos-design-system@40.0.0
Malicious code in @united-airlines-org/atmos-design-system (npm)
T1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The package's preinstall hook runs curl against the attacker-controlled host bxss[.]boll-sec[.]de, appending the machine's hostname base64-encoded as a URL path segment (hostname_<base64>). On every install it exfiltrates the hostname of the installing machine to this remote host. The package ships no code, README, or license — only the malicious install hook.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 03:23 PM
- analyzed
- Aug 6, 2026, 03:24 PM
Related advisories
- hojamalo-scanner@1.0.0
- streak-cache-map@1.0.0
- clients-structure@35.9.8
- cnb-cnb-core@35.2.7
- cobrowsing-cobrowsing-core@35.5.8
- ezdiscordbots@1.0.2
- cobrowsing-configs@35.7.5
- cobrowsing-decorators@35.2.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.