LWA-2026-2164 confirmed malware

@catamania/front-components@1.0.2

Malicious code in @catamania/front-components (npm)

T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages

Analysis

@catamania/front-components@1.0.2 is disguised as a UI components library with a trivial decoy Vue component. Its postinstall hook collects hostname, username, current working directory and environment-variable keys and POSTs them to hxxps://webhook[.]site/9bbf9333-af82-4597-90d8-7da9162ed500. There is no README or repository URL. This is a host-metadata reconnaissance beacon aimed at identifying high-value targets.

analyzed by
Leitwacht
first seen
Jun 1, 2026, 10:51 AM
analyzed
Jun 1, 2026, 11:24 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.