@dxcl/user-js@99.99.99
Malicious code in @dxcl/user-js (npm)
T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1071.004 · DNST1041 · Exfiltration Over C2 Channel
Analysis
Version-squatting supply-chain attack. Package @dxcl/user-js@99.99.99 is a tiny stub (983 bytes) whose preinstall and install hooks both collect the installer's username, hostname, current working directory, and the package name, base64-encode that data, and exfiltrate it via curl to hxxps://{package-name-encoded}[.]callback[.]m0chan[.]co[.]uk/{base64-payload}. The hooks also perform DNS-based exfiltration of the package name via nslookup to the same callback[.]m0chan[.]co[.]uk domain.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 11:22 AM
- analyzed
- Jun 18, 2026, 11:23 AM
Related advisories
- @dxcl/http-common-js@99.99.99
- @dxcl/fund-js@99.99.99
- @dxcl/indicators-js@99.99.99
- ug-env-switch-ball@7.9.9
- tdhg-demp@1.0.0
- sftc-advance-components@0.9.9
- rtms-manager@1.0.0
- reseller-app@9.9.11
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.