LWA-2026-6580 MAL-2026-10150 ↗ confirmed malware

ap3-components-ui@9.999.0

Malicious code in ap3-components-ui (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.004 · DNS

Analysis

ap3-components-ui@9.999.0 is a combosquat package that runs a host-reconnaissance and data-exfiltration payload on preinstall. The preinstall hook executes a shell command that collects the hostname, current working directory, username, and external IP address (via ifconfig[.]me), hex-encodes the collected data, and exfiltrates it via DNS lookups to the OAST callback domain d987f5ra3q1r1j7ahol0yzuwujwe76i55[.]oast[.]fun. The package contains only two files (index.js and package.json) totaling 564 bytes, has no repository, and its declared main.js does not exist.

analyzed by
Leitwacht
first seen
Jul 10, 2026, 05:38 AM
analyzed
Jul 10, 2026, 05:39 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.