@dbbhk/ui-components@99.0.0
Malicious code in @dbbhk/ui-components (npm)
Analysis
The package @dbbhk/ui-components (version 99.0.0) impersonates an internal HSBC UI-components package and runs a credential-harvesting payload in both its preinstall and postinstall hooks (node callback.js). The payload reads AWS IMDS metadata and IAM role credentials from 169[.]254[.]169[.]254, ECS task-role credentials from 169[.]254[.]170[.]2, environment variables matching AWS/SECRET/KEY/TOKEN/PASSWORD/CREDENTIAL/AUTH/API/NPM/GITHUB/GITLAB patterns, and credential files including ~/.aws/credentials, ~/.npmrc, /root/.aws/credentials, .env, and the Kubernetes service-account token. It then POSTs the harvested host metadata and credential values (truncated to their first 8-10 characters) to a Telegram bot at api[.]telegram[.]org.
- analyzed by
- Leitwacht
- first seen
- Sep 20, 2026, 09:27 AM
- analyzed
- Sep 20, 2026, 09:28 AM
Related advisories
- @evial/init-helper-djkwt@1.0.0
- fmt-util-k7x2@1.0.0
- simple-date-formatter-util-11@1.0.0
- simple-date-formatter-util-4@1.0.0
- string-formatter-pro@1.0.0
- ripshakti@80.0.0
- anthropic-internal-tools@1.0.0
- date-format-helper2@1.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.