LWA-2026-2164 confirmed malware
@catamania/front-components@1.0.2
Malicious code in @catamania/front-components (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
@catamania/front-components@1.0.2 is disguised as a UI components library with a trivial decoy Vue component. Its postinstall hook collects hostname, username, current working directory and environment-variable keys and POSTs them to hxxps://webhook[.]site/9bbf9333-af82-4597-90d8-7da9162ed500. There is no README or repository URL. This is a host-metadata reconnaissance beacon aimed at identifying high-value targets.
- analyzed by
- Leitwacht
- first seen
- Jun 1, 2026, 10:51 AM
- analyzed
- Jun 1, 2026, 11:24 AM
Related advisories
- @convera/ui-shared@0.0.2
- @convera/ui-shared@0.0.3
- msc-terminal@3.2.0
- @asavie/i18n@99.0.3
- forge-jsxy@1.0.91
- eslint-plugin-vitest-ts@1.0.4
- fundraiserserv@28.0.0
- relativity-pdfjs-dist@99.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.