@hzero-front-ui/c7n-ui@99.99.99
Malicious code in @hzero-front-ui/c7n-ui (npm)
Analysis
The package is a dependency-confusion stub (scoped name, version 99.99.99, ~500-byte tarball with no functional code). Its preinstall and install hooks base64-encode the installer's username, hostname, working directory and package name, then exfiltrate that metadata to the attacker-controlled callback domain callback[.]m0chan[.]co[.]uk via an HTTP GET to hxxps://<pkgsub>.callback[.]m0chan[.]co[.]uk/<base64> and a DNS lookup of a base64-encoded subdomain of the same host. Installing the package leaks host/user/cwd information to the remote callback server.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 08:43 PM
- analyzed
- Aug 13, 2026, 08:43 PM
Related advisories
- @hzero-front-ui/themes@99.99.99
- @hzero-front-ui/cfg@99.99.99
- @hzero-front-ui/hzero-ui@99.99.99
- @hzero-front-ui/core@99.99.99
- notafollower@1.0.0
- cilm-ui-commons@1.1.0
- async-lock-queue@3.0.1
- functions-framework-nodejs@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.