LWA-2026-11174 confirmed malware

cilm-ui-commons@1.1.0

Malicious code in cilm-ui-commons (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall hook runs index.js, which collects host metadata (hostname, username, home directory, DNS server list, and the full package.json) and POSTs it to the remote endpoint eogo57c0daum9d3[.]m[.]pipedream[.]net over HTTPS. The exfiltration runs automatically on install with no user consent.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 12:23 PM
analyzed
Aug 13, 2026, 12:23 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.