LWA-2026-11186 confirmed malware
bootstrap-custom-ui@5.7.2
Malicious code in bootstrap-custom-ui (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
bootstrap-custom-ui@5.7.2 is a remote-code-execution dropper disguised as a React UI component library. Its main entry point (index.js) fetches a payload from hxxp://31[.]97[.]137[.]157:45000/icons/108 (sending a custom 'bearrtoken: logo' header) and executes the response body's 'credits' field via the Function constructor with a full Node.js context (require, process, Buffer, globalThis, timers), giving the remote server arbitrary code execution on the installer's machine. The package ships no actual UI components despite its documentation.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 06:14 PM
- analyzed
- Aug 13, 2026, 06:15 PM
Related advisories
- datetime-fmt-xutil@1.0.0
- core-js-buffer@1.0.0
- shared-slot-gate@1.1.2
- semaphore-job-pool@2.2.2
- postcss-initialize-plugin@3.0.4
- cc-skills-helper@1.0.0
- my-auto-follow@1.0.0
- in-install@99.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.