@feui-render/feui-render@99.0.0
Malicious code in @feui-render/feui-render (npm)
Analysis
Package @feui-render/feui-render@99.0.0 is a dependency-confusion proof-of-concept published under an authorized bug bounty engagement. On install, the preinstall script (scripts/preinstall.js) sends a single HTTPS POST to callback[.]kuldeep[.]io/beacon containing the machine hostname, Node.js version, platform, package name/version, and a correlation nonce. No environment variables, credentials, tokens, or filesystem data are collected or exfiltrated. No shell execution, persistence, or additional downloads occur. The package is a placeholder to demonstrate that an internal package name resolves from the public registry.
- analyzed by
- Leitwacht
- first seen
- Jul 27, 2026, 12:53 PM
- analyzed
- Jul 27, 2026, 12:55 PM
Related advisories
- animate-css-vite@1.0.1
- vscode-designer-14@14.0.1
- encrypt-string-safe@2.1.0
- dateuuidv2@1.0.0
- dynstrg-howto@1.0.1
- compress-edge@1.0.0
- page-navigation@1.0.1
- xo-member-components@28.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.