LWA-2026-6462 confirmed malware
cdc-market@99.9.9
Malicious code in cdc-market (npm)
T1195.002 · Compromise Software Supply ChainT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
cdc-market@99.9.9 exfiltrates system information on require(). The package collects the installer's username, current working directory, hostname, and local IP address, then POSTs the data as JSON to hxxps://webhook[.]site/43a8680e-b580-40f5-b7aa-f089ac659712. The package has no repository, no description, and was published at version 99.9.9 — consistent with a dependency-confusion or combosquat attack targeting a legitimate package name.
- analyzed by
- Leitwacht
- first seen
- Jul 8, 2026, 12:37 PM
- analyzed
- Jul 8, 2026, 12:38 PM
Related advisories
- playerdata-core@9.9.1
- @vwfs-its/sf-sac-frontend@20.1.1
- dependency_confusions@99.9.9
- @comcastdevxplatforms/plugin-tenancyinformation@28.1.1
- @devxprotect/plugin-devxprotect-experience@22.2.1
- @devxdiscover/devhub-ui@24.1.4
- cpcz-common@22.1.1
- react-dom-v17@22.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.