Logo
npm

@corpweb-ui/wmkt-library@99.99.12

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 4:37 AM UTC

Malicious

OSV ID

MAL-2026-2446

Ecosystem

npm

Summary

index.js uses child_process to execute whoami and gather hostname information, then transmits results via https.get to api.telegram.org/bot — a well-known pattern for Telegram-bot-based C2/exfiltration. The package name mimics a corporate UI library but the code performs system reconnaissance and exfiltration of installer host data, with no legitimate UI-library functionality indicated at the entry point. Any installer or build system that pulls this package will leak the machine's user and hostname to an attacker-controlled Telegram bot on require/load. Three independent static detections (child-process + https exfiltration, nodejs system exfiltration, simple sysinfo exfiltration) corroborate a single small file implementing a classic recon beacon.

Source: amazon-inspector (dfd12ddf708e12b032513bcf667e459df772f642106507d1798d95ee81f6cbe2)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.