shadcn-ui-autocomplete@3.5.0
Malicious code in shadcn-ui-autocomplete (npm)
Analysis
shadcn-ui-autocomplete@3.5.0 is a browser credential stealer that combosquats the shadcn/ui component library. On npm install, the postinstall hook runs an obfuscated JavaScript file (output.js) that enumerates browser profiles for Chrome, Edge, Brave, Opera, Firefox, Vivaldi, and Chromium. It reads saved passwords (Login Data SQLite databases), cookies, and browser encryption keys (Local State) from the victim's %APPDATA% and %LOCALAPPDATA% directories. The stolen data is exfiltrated to a remote C2 endpoint (URL obfuscated and decoded at runtime). The package has no legitimate functionality — empty description, no repository, no README.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 09:32 PM
- analyzed
- Jun 13, 2026, 09:34 PM
Related advisories
- polymarket-gamma-apis@1.4.0
- pocbitbarrontest@1.0.0
- period-newline@0.1.0
- index-ulid@3.0.2
- gpt-terminal-cli@1.0.0
- wormgpt-cli@1.0.1
- streak-cache-map@1.0.0
- streak-math-calc@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.