MAL-2026-16201
Malicious code in webpackbootstrap5 (npm)
Details
webpackbootstrap5@5.0.0 typosquats bootstrap and ships a disguised in-browser proxy kit. Its bundled loader (index-z2b7r4.js) XOR-decodes a list of endpoints with a fixed key and injects remote scripts from https://dyingefforlessefforlessours.com via document.head.appendChild, then boots a Scramjet/wisp WebSocket proxy that routes page traffic through operator-controlled relays. The loader matches (same sha256) sibling packages webpackbootstrapscripts and @zaka13/thing by the same publisher (zaka13). Harm is browser-side when the asset is served; no install script runs.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for webpackbootstrap5 (npm). Pin to a known-safe version or switch to an alternative.