@hzero-front-ui/hzero-ui@99.99.99
Malicious code in @hzero-front-ui/hzero-ui (npm)
Analysis
@hzero-front-ui/hzero-ui@99.99.99 is a version-squat stub (99.99.99, ~500-byte tarball) on a scoped name mimicking the hzero-ui UI library. Its preinstall and install hooks both run on install: they base64-encode the installer's username, hostname, and working directory together with the package name, POST that string to hxxps://<pkgsub>.callback[.]m0chan[.]co[.]uk/<b64> via curl, and also exfiltrate the base64-encoded package name via an nslookup DNS query to <pkgdns>.<pkgsub>.callback[.]m0chan[.]co[.]uk. The package exfiltrates host metadata to the callback domain m0chan[.]co[.]uk on every install.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 08:28 PM
- analyzed
- Aug 13, 2026, 08:30 PM
Related advisories
- @hzero-front-ui/c7n-ui@99.99.99
- @hzero-front-ui/themes@99.99.99
- @hzero-front-ui/cfg@99.99.99
- dolyame-ui-grid@35.7.4
- @onereach/slack-helpers@1.0.5
- @digiptf/common@99.99.99
- hunsterx-package@7.0.1
- search-from-feed@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.