LWA-2026-4021 confirmed malware
mpesa-ui-components@1.1.20
Malicious code in mpesa-ui-components (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
During npm install (preinstall: node index.js), mpesa-ui-components collects hostname, username, homedir, cwd, DNS servers and the full package.json, then POSTs the JSON payload to hxxps://m-pesa[.]cleverapps[.]io/api/data/(hostname). Two HTTPS POSTs were observed. The package is two files (~812-byte index.js plus package.json) with zero UI components despite its name — a pure install-time host-fingerprint beacon.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 08:57 PM
- analyzed
- Jun 10, 2026, 08:58 PM
Related advisories
- motion-lib@2.3.5
- hex-type@3.0.2
- moltbook-api-helper@1.0.1
- miro-plugin-tag-crawler@1.0.0
- mimecast-web-components@2.0.0
- websocket-slot@0.0.6
- yelp-react-component-chaos@8.14.5
- maninos@1.2.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.