dependency_confusions@99.9.9
Malicious code in dependency_confusions (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
Dependency-confusion package (name "dependency_confusions" at version 99.9.9) with a postinstall hook that runs index.js. The script collects the installer's username, hostname, current working directory, local IP address, and platform, then POSTs this data as JSON to webhook[.]site/264e1903-28ea-48ea-8c55-be58c5a76791. The webhook[.]site service is a third-party webhook receiver commonly used for data exfiltration.
- analyzed by
- Leitwacht
- first seen
- Jul 8, 2026, 09:44 AM
- analyzed
- Jul 8, 2026, 09:44 AM
Related advisories
- @comcastdevxplatforms/plugin-tenancyinformation@28.1.1
- @devxprotect/plugin-devxprotect-experience@22.2.1
- @devxdiscover/devhub-ui@24.1.4
- cpcz-common@22.1.1
- react-dom-v17@22.1.1
- rio-design-tokens@99.99.99
- hello244b@1.0.0
- sn-flow-client@20.5.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.