LWA-2026-12276 MAL-2026-16319 ↗ confirmed malware

@dbbhk/ui-components@99.0.0

Malicious code in @dbbhk/ui-components (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.005 · Cloud Instance Metadata APIT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package @dbbhk/ui-components (version 99.0.0) impersonates an internal HSBC UI-components package and runs a credential-harvesting payload in both its preinstall and postinstall hooks (node callback.js). The payload reads AWS IMDS metadata and IAM role credentials from 169[.]254[.]169[.]254, ECS task-role credentials from 169[.]254[.]170[.]2, environment variables matching AWS/SECRET/KEY/TOKEN/PASSWORD/CREDENTIAL/AUTH/API/NPM/GITHUB/GITLAB patterns, and credential files including ~/.aws/credentials, ~/.npmrc, /root/.aws/credentials, .env, and the Kubernetes service-account token. It then POSTs the harvested host metadata and credential values (truncated to their first 8-10 characters) to a Telegram bot at api[.]telegram[.]org.

analyzed by
Leitwacht
first seen
Sep 20, 2026, 09:27 AM
analyzed
Sep 20, 2026, 09:28 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.