LWA-2026-6387 MAL-2026-10656 ↗ confirmed malware

@pimy-b2cweb/frontend-lib@99.99.99

Malicious code in @pimy-b2cweb/frontend-lib (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Dependency-confusion packages published under the @pimy-b2cweb scope at version 99.99.99. Both preinstall and install hooks collect system information (username, hostname, working directory, package name) via base64-encoded HTTPS GET requests and DNS lookups to callback[.]m0chan[.]co[.]uk. The hooks run curl and nslookup to exfiltrate the encoded data to the C2 domain.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 09:07 AM
analyzed
Jul 7, 2026, 01:12 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.