LWA-2026-11375 confirmed malware

colorpicker-ui@1.2.6

Malicious code in colorpicker-ui (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1057 · Process DiscoveryT1016 · System Network Configuration DiscoveryT1083 · File and Directory DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The postinstall hook (setup.js) of this "React color picker" package runs a reconnaissance and exfiltration implant on install. It collects host identity (hostname, user, kernel, machine-id, capabilities, seccomp), performs sandbox detection, and harvests cloud credentials from AWS EC2 metadata (IMDSv1 and IMDSv2 IAM role security credentials), GCP metadata (service-account token), and Azure metadata (identity token), plus any Kubernetes service-account token. It enumerates network interfaces, routes, and listening ports, port-scans localhost, the gateway, and the first 20 subnet IPs, and probes processes, filesystem, sudo/cron/capabilities for privilege escalation. All collected data is POSTed in chunks to hxxps://webhook[.]site/3dc365ff-07dd-42e6-b5e7-e707736401fb.

analyzed by
Leitwacht
first seen
Aug 16, 2026, 09:39 AM
analyzed
Aug 16, 2026, 09:40 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.