colorpicker-ui@1.2.6
Malicious code in colorpicker-ui (npm)
Analysis
The postinstall hook (setup.js) of this "React color picker" package runs a reconnaissance and exfiltration implant on install. It collects host identity (hostname, user, kernel, machine-id, capabilities, seccomp), performs sandbox detection, and harvests cloud credentials from AWS EC2 metadata (IMDSv1 and IMDSv2 IAM role security credentials), GCP metadata (service-account token), and Azure metadata (identity token), plus any Kubernetes service-account token. It enumerates network interfaces, routes, and listening ports, port-scans localhost, the gateway, and the first 20 subnet IPs, and probes processes, filesystem, sudo/cron/capabilities for privilege escalation. All collected data is POSTed in chunks to hxxps://webhook[.]site/3dc365ff-07dd-42e6-b5e7-e707736401fb.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 09:39 AM
- analyzed
- Aug 16, 2026, 09:40 AM
Related advisories
- stellarfixer@1.0.0
- simple-date-formatter-util-12@1.0.0
- twork-data-services-customer-api-v2-customer-vip-status@20.9.7
- streak-int-lib@1.0.0
- text-line-parser@1.0.0
- date-sanitize-helper@1.0.0
- n8n-nodes-utils-helper@1.0.0
- n8n-nodes-task-runner@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.