colorpicker-ui@1.2.6
Malicious code in colorpicker-ui (npm)
Analysis
The postinstall hook (setup.js) of this "React color picker" package runs a reconnaissance and exfiltration implant on install. It collects host identity (hostname, user, kernel, machine-id, capabilities, seccomp), performs sandbox detection, and harvests cloud credentials from AWS EC2 metadata (IMDSv1 and IMDSv2 IAM role security credentials), GCP metadata (service-account token), and Azure metadata (identity token), plus any Kubernetes service-account token. It enumerates network interfaces, routes, and listening ports, port-scans localhost, the gateway, and the first 20 subnet IPs, and probes processes, filesystem, sudo/cron/capabilities for privilege escalation. All collected data is POSTed in chunks to hxxps://webhook[.]site/3dc365ff-07dd-42e6-b5e7-e707736401fb.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 09:39 AM
- analyzed
- Aug 16, 2026, 09:40 AM
Related advisories
- wormgpt-cli@1.0.1
- streak-metrics-core@1.0.0
- @cryptosrvc/shift-sdk-v4@1.0.77
- @shiftmarkets/shift-exchange-root@3.9.9
- system-performance-helper@1.0.1
- n8n-nodes-port-scanner@1.0.0
- react-campaign-optimizer@1.0.0
- search-from-search@999.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.