LWA-2026-5366 confirmed malware

umi-preset-rce-jytest@1.0.1

Malicious code in umi-preset-rce-jytest (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1005 · Data from Local System

Analysis

An Umi.js build plugin that harvests system and environment information during the build phase. When a project using this dependency is built, the plugin executes shell commands to collect: hostname, username, current working directory, Node/npm versions, the full environment variable listing (capturing any CI/CD tokens such as NPM_TOKEN, GITHUB_TOKEN, or AWS credentials present in the environment), network configuration, process list, disk usage, network connections, /etc/passwd (first 20 lines), and /etc/hosts. All collected data is written to a file named rce-debug.log in the build output directories (dist, build, out, output, public). Additionally, the data is base64-encoded and injected as an HTML comment (prefixed JYRCE::) into every .html file in those directories. No outbound network traffic was observed from this package itself; the stolen data is exfiltrated through contaminated build artifacts.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 10:42 AM
analyzed
Jun 15, 2026, 10:44 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.