@dsft/ft-element@2.5.9
Malicious code in @dsft/ft-element (npm)
Analysis
This package runs a preinstall lifecycle hook that executes automatically when the package is installed. At install time it reads the installing project's working directory and captures the project folder name, then sends that information together with a timestamp and the package name as a JSON POST request to a hardcoded remote callback URL. This is dependency-confusion beacon behaviour: install-time code execution that exfiltrates host/project identity to an external attacker-controlled server without consent.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 04:26 PM
- analyzed
- Jun 16, 2026, 04:56 PM
Related advisories
browse all confirmed advisories →Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.