umber-root@1.1.2
Malicious code in umber-root (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
The postinstall hook (node dist/config.js) fetches a payload from hxxps://my-api[.]trade-api[.]workers[.]dev?id=3 and executes the response as arbitrary JavaScript code via dynamic function invocation. The C2 server controls what code runs on the installer's machine. The package ships a legitimate-looking color-toolkit library in src/ to appear benign, while the install-time payload provides a remote-code-execution backdoor.
- analyzed by
- Leitwacht
- first seen
- Jul 27, 2026, 03:09 PM
- analyzed
- Jul 27, 2026, 03:10 PM
Related advisories
- npm-wold@1.1.1
- animate-css-vite@1.0.1
- encrypt-string-safe@2.1.0
- dateuuidv2@1.0.0
- app-sim-layer@2.1.6
- app-node-layer@2.1.6
- chai-as-rendered@1.2.0
- @daylightqc/date-fmt-lite@1.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.