@coze-common/chat-area@99.1.1
Malicious code in @coze-common/chat-area (npm)
Analysis
@coze-common/chat-area@99.1.1 is a dependency-confusion malware. Version-squatted at 99.1.1 (3 files, 1.8KB, 1 version) pretending to be a @coze-platform utility. Publisher [account] Postinstall.js collects hostname, username, CWD, and filesystem directory tree (depth 2, 15 entries), then exfiltrates via HTTPS POST (base64) to wybqtvzmfhssbvhokfgbvgaalpfg1vneq[.]oast[.]fun — a known OOB-style exfil endpoint. Also uses DNS lookup with hex-encoded hostname+username as a fallback side-channel. No token-theft markers, but the install-triggered beacon alone is malicious.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 10:28 PM
- analyzed
- Jun 10, 2026, 10:29 PM
Related advisories
- mw-filesystem-events-nodream_compat@99.99.99
- mw-filesystem-events-nodream-es6@0.0.32
- mw-filesystem-events-nodream@0.0.32
- mpesa-ui-components@1.1.20
- motion-lib@2.3.5
- hex-type@3.0.2
- moltbook-api-helper@1.0.1
- miro-plugin-tag-crawler@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.