LWA-2026-5369 confirmed malware

unicode-colors@4.1.4

Malicious code in unicode-colors (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1497 · Virtualization/Sandbox EvasionT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1195.002 · Compromise Software Supply Chain

Analysis

Package unicode-colors@4.1.4 carries a malicious preinstall script (dist/util.js) that runs on 'npm install'. The script evades detection by checking for virtualized environments (VMware, VirtualBox, KVM, Hyper-V MAC address prefixes), available CPU cores, free memory, system uptime (<2 hours), and sandbox hostnames. If no sandbox is detected, it makes an HTTPS request to an obfuscated C2 server and executes the response body via eval() — a second-stage remote code execution payload. The package is named misleadingly "unicode-colors" but ships the unrelated LayUI front-end framework as cover. It executes arbitrary code from its C2 on every install.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 10:59 AM
analyzed
Jun 15, 2026, 11:00 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.