mermaid-v11@9999.0.0
Malicious code in mermaid-v11 (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1071.004 · DNST1041 · Exfiltration Over C2 Channel
Analysis
mermaid-v11 combosquats the real mermaid diagramming library. The package contains only a package.json with a preinstall hook that collects hostname and username via os.hostname() and os.userInfo().username, then exfiltrates them to d8ks495t5p5ut2enft8041g7fusnfsy5e[.]oast[.]site via both an HTTPS GET and a DNS lookup (using the subdomain as a side channel). Version 9999.0.0 and the absence of any real library code confirm a combosquat reconnaissance beacon.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 12:35 AM
- analyzed
- Jun 11, 2026, 12:35 AM
Related advisories
- mimecast-web-components@2.0.0
- sme-rko-finance-front-operations-notifications-impl@35.8.1
- dolyame-ui-cardlogo@35.8.1
- dolyame-ui-contextmenu@35.8.1
- dolyame-ui-contenteditable@35.8.1
- dolyame-ui-mediainfohoc@35.8.1
- dolyame-ui-inputtime@35.8.1
- dolyame-ui-selectaccount@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.