LWA-2026-6386 confirmed malware
@pimy-b2cweb/common@99.99.99
Malicious code in @pimy-b2cweb/common (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Dependency-confusion packages published under the @pimy-b2cweb scope at version 99.99.99. Both preinstall and install hooks collect system information (username, hostname, working directory, package name) via base64-encoded HTTPS GET requests and DNS lookups to callback[.]m0chan[.]co[.]uk. The hooks run curl and nslookup to exfiltrate the encoded data to the C2 domain.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 09:07 AM
- analyzed
- Jul 7, 2026, 01:12 PM
Related advisories
- @pimy-b2cweb/frontend-lib@99.99.99
- @pimy-b2cweb/apiclient-common@99.99.99
- @pimy-b2cweb/apiclient-b2cweb-r2@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.