LWA-2026-11174 confirmed malware
cilm-ui-commons@1.1.0
Malicious code in cilm-ui-commons (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The package's preinstall hook runs index.js, which collects host metadata (hostname, username, home directory, DNS server list, and the full package.json) and POSTs it to the remote endpoint eogo57c0daum9d3[.]m[.]pipedream[.]net over HTTPS. The exfiltration runs automatically on install with no user consent.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 12:23 PM
- analyzed
- Aug 13, 2026, 12:23 PM
Related advisories
- async-lock-queue@3.0.1
- functions-framework-nodejs@1.0.0
- core-js-buffer@1.0.0
- shared-slot-gate@1.1.2
- try-lock-runner@3.2.1
- priority-mutex-lane@2.5.1
- resource-lease-pool@1.4.2
- semaphore-job-pool@2.2.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.