LWA-2026-5583 MAL-2026-5889 ↗ confirmed malware

@dsft/ft-element@2.5.9

Malicious code in @dsft/ft-element (npm)

Analysis

This package runs a preinstall lifecycle hook that executes automatically when the package is installed. At install time it reads the installing project's working directory and captures the project folder name, then sends that information together with a timestamp and the package name as a JSON POST request to a hardcoded remote callback URL. This is dependency-confusion beacon behaviour: install-time code execution that exfiltrates host/project identity to an external attacker-controlled server without consent.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 04:26 PM
analyzed
Jun 16, 2026, 04:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.