web-model-bridge@9999.99.99
Malicious code in web-model-bridge (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
A dependency-confusion version-squatting package published at version 9999.99.99 that proxies through to the real web-model-bridge module to stay hidden while running a postinstall reconnaissance beacon. The hook POSTs a JSON payload containing OS, Node version, a CI indicator, and GITHUB_REPOSITORY/GITHUB_REPOSITORY_OWNER/GITHUB_WORKFLOW to hxxps://ddactic-lab[.]online/sc/beacon, with a DNS-based fallback beacon encoded as a subdomain label on b[.]ddactic-lab[.]online.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 06:31 AM
- analyzed
- Jun 12, 2026, 06:32 AM
Related advisories
- period-newline@0.1.0
- peptideenv@16.6.6
- packageuwu@1.0.1
- paasprint-sdk@9.9.9
- coral-wraith@1.0.4
- worker-build@9.0.1
- index-ulid@3.0.2
- npm-scanner@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.