@variational/common-ui@99.0.0
Malicious code in @variational/common-ui (npm)
Analysis
@variational/common-ui@99.0.0 is a dependency-confusion (version-squat) package that exfiltrates CI/CD credentials. The preinstall hook runs callback.js, which reads process.env (harvesting npm/GitHub/AWS/OpenAI/Anthropic/Stripe/Slack/DigitalOcean/Netlify/Cloudflare/Twilio/SendGrid/PyPI/HuggingFace/GitLab/Docker/Cargo/Vercel tokens and secrets), hostname, platform, user info, network config, and POSTs the collected data to hxxp://2[.]25[.]186[.]116:8443/variational-depconf. The package is a 876-byte stub published at version 99.0.0 to exploit CI environments that automatically install scoped packages at high versions.
- analyzed by
- Leitwacht
- first seen
- Jun 21, 2026, 10:55 AM
- analyzed
- Jun 21, 2026, 10:56 AM
Related advisories
- @npmresearch3/metrics-probe-dfda@1.0.0
- metrics-probe-9b4c@1.0.0
- @velkov/viem@2.53.1
- local-ip-helper@0.1.0
- ts-bn-lint-helper@3.1.19
- atlasora-client@1.0.0
- atlasora-utils@1.0.0
- atlasora-types@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.