LWA-2026-5810 confirmed malware

@variational/common-ui@99.0.0

Malicious code in @variational/common-ui (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

@variational/common-ui@99.0.0 is a dependency-confusion (version-squat) package that exfiltrates CI/CD credentials. The preinstall hook runs callback.js, which reads process.env (harvesting npm/GitHub/AWS/OpenAI/Anthropic/Stripe/Slack/DigitalOcean/Netlify/Cloudflare/Twilio/SendGrid/PyPI/HuggingFace/GitLab/Docker/Cargo/Vercel tokens and secrets), hostname, platform, user info, network config, and POSTs the collected data to hxxp://2[.]25[.]186[.]116:8443/variational-depconf. The package is a 876-byte stub published at version 99.0.0 to exploit CI environments that automatically install scoped packages at high versions.

analyzed by
Leitwacht
first seen
Jun 21, 2026, 10:55 AM
analyzed
Jun 21, 2026, 10:56 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.