LWA-2026-11208 MAL-2026-13967 ↗ confirmed malware

@hzero-front-ui/c7n-ui@99.99.99

Malicious code in @hzero-front-ui/c7n-ui (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package is a dependency-confusion stub (scoped name, version 99.99.99, ~500-byte tarball with no functional code). Its preinstall and install hooks base64-encode the installer's username, hostname, working directory and package name, then exfiltrate that metadata to the attacker-controlled callback domain callback[.]m0chan[.]co[.]uk via an HTTP GET to hxxps://<pkgsub>.callback[.]m0chan[.]co[.]uk/<base64> and a DNS lookup of a base64-encoded subdomain of the same host. Installing the package leaks host/user/cwd information to the remote callback server.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 08:43 PM
analyzed
Aug 13, 2026, 08:43 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.