LWA-2026-11186 confirmed malware

bootstrap-custom-ui@5.7.2

Malicious code in bootstrap-custom-ui (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

bootstrap-custom-ui@5.7.2 is a remote-code-execution dropper disguised as a React UI component library. Its main entry point (index.js) fetches a payload from hxxp://31[.]97[.]137[.]157:45000/icons/108 (sending a custom 'bearrtoken: logo' header) and executes the response body's 'credits' field via the Function constructor with a full Node.js context (require, process, Buffer, globalThis, timers), giving the remote server arbitrary code execution on the installer's machine. The package ships no actual UI components despite its documentation.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 06:14 PM
analyzed
Aug 13, 2026, 06:15 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.