LWA-2026-4021 confirmed malware

mpesa-ui-components@1.1.20

Malicious code in mpesa-ui-components (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

During npm install (preinstall: node index.js), mpesa-ui-components collects hostname, username, homedir, cwd, DNS servers and the full package.json, then POSTs the JSON payload to hxxps://m-pesa[.]cleverapps[.]io/api/data/(hostname). Two HTTPS POSTs were observed. The package is two files (~812-byte index.js plus package.json) with zero UI components despite its name — a pure install-time host-fingerprint beacon.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 08:57 PM
analyzed
Jun 10, 2026, 08:58 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.