LWA-2026-5660 MAL-2026-6069 ↗ confirmed malware

@civitatis/bot-ui@15.12.11

Malicious code in @civitatis/bot-ui (npm)

Analysis

This package contains no legitimate functionality. Its package.json declares a preinstall hook (node index.js) that runs automatically on installation. The script collects host reconnaissance data — hostname, OS platform/release/architecture, the current user (username, uid, gid, login shell, home directory), CPU and memory details, the working directory, and the output of the whoami and id shell commands — then serializes it as JSON and sends it via an HTTP POST to a hardcoded external collaborator endpoint. This is install-time system-information exfiltration consistent with a dependency-confusion reconnaissance payload.

analyzed by
Leitwacht
first seen
Jun 17, 2026, 03:10 PM
analyzed
Jun 17, 2026, 03:21 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.