@civitatis/bot-ui@15.12.11
Malicious code in @civitatis/bot-ui (npm)
Analysis
This package contains no legitimate functionality. Its package.json declares a preinstall hook (node index.js) that runs automatically on installation. The script collects host reconnaissance data — hostname, OS platform/release/architecture, the current user (username, uid, gid, login shell, home directory), CPU and memory details, the working directory, and the output of the whoami and id shell commands — then serializes it as JSON and sends it via an HTTP POST to a hardcoded external collaborator endpoint. This is install-time system-information exfiltration consistent with a dependency-confusion reconnaissance payload.
- analyzed by
- Leitwacht
- first seen
- Jun 17, 2026, 03:10 PM
- analyzed
- Jun 17, 2026, 03:21 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.