VDB
Sign up

MAL-2026-16201

Malicious code in webpackbootstrap5 (npm)

Details

webpackbootstrap5@5.0.0 typosquats bootstrap and ships a disguised in-browser proxy kit. Its bundled loader (index-z2b7r4.js) XOR-decodes a list of endpoints with a fixed key and injects remote scripts from https://dyingefforlessefforlessours.com via document.head.appendChild, then boots a Scramjet/wisp WebSocket proxy that routes page traffic through operator-controlled relays. The loader matches (same sha256) sibling packages webpackbootstrapscripts and @zaka13/thing by the same publisher (zaka13). Harm is browser-side when the asset is served; no install script runs.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/webpackbootstrap5

No fixed version published yet for webpackbootstrap5 (npm). Pin to a known-safe version or switch to an alternative.