webrix-docs@19.2.11
Malicious code in webrix-docs (npm)
Analysis
webrix-docs is a typosquat of the legitimate webix-docs documentation package. The package has no repository, no description, and a high version number (19.2.11) on its first and only publication. It installs a preinstall hook that runs node index.js on install, automatically executing the package's main entry point without the installer's knowledge or consent. The package was published under a name that differs from the real webix-docs by one character (webrix vs webix), intended to catch typo-prone installs and run code on the victim's machine during npm install.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 03:44 PM
- analyzed
- Jul 2, 2026, 03:45 PM
Related advisories
- chai-as-align@7.1.0
- db-query-log@1.0.2
- marked-prettier@1.0.5
- execfences@5.0.2
- compose-logger-stand@1.0.126
- react-jsonwebtoken@9.0.5
- datefmt-helper@1.0.0
- lusha-iam-widgets@1.5.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.