LWA-2026-6457 MAL-2026-10085 ↗ confirmed malware

dependency_confusions@99.9.9

Malicious code in dependency_confusions (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Dependency-confusion package (name "dependency_confusions" at version 99.9.9) with a postinstall hook that runs index.js. The script collects the installer's username, hostname, current working directory, local IP address, and platform, then POSTs this data as JSON to webhook[.]site/264e1903-28ea-48ea-8c55-be58c5a76791. The webhook[.]site service is a third-party webhook receiver commonly used for data exfiltration.

analyzed by
Leitwacht
first seen
Jul 8, 2026, 09:44 AM
analyzed
Jul 8, 2026, 09:44 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.