Malicious code in dc-renewals-layout2 (npm)
The npm package dc-renewals-layout2 version 9999.0.0 contains malicious code in its preinstall script that executes automatically during installation. This script sends a plaintext HTTP GET request to a hardcoded IP address on a non-standard port, transmitting sensitive environment information such as the installer's hostname, username, current working directory, npm registry, and CI repository slug. This behavior is identified as a dependency-confusion reconnaissance beacon, which can reveal private internal package names and enable targeted attacks against the installer's organization.
AI Analysis
Technical Summary
The dc-renewals-layout2 npm package version 9999.0.0 includes a preinstall script that auto-runs on npm install. This script issues a plaintext HTTP GET request to http://75.119.137.232:31337/depconfuse, sending query parameters containing the installer's hostname, username, current working directory, configured npm registry, and CI repository slug environment variables. The presence of the /depconfuse endpoint and the version fingerprint indicates a dependency-confusion reconnaissance beacon. The CI repository slug can disclose private internal package or repository names, facilitating targeted dependency-confusion attacks. The destination IP and port are unrelated to the package's declared purpose, indicating malicious intent.
Potential Impact
Sensitive environment information from the installer's system and CI environment is exfiltrated to an attacker-controlled server. This leakage can disclose private internal package names and repository details, enabling attackers to craft targeted dependency-confusion attacks against the affected organization. While no direct exploit in the wild is known, the reconnaissance activity poses a significant risk of follow-on supply chain attacks.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing the dc-renewals-layout2 package version 9999.0.0. Review and audit dependencies for unexpected preinstall scripts and network calls. Monitor for suspicious outbound connections during package installation. Check vendor advisories or trusted security sources for updates or patches addressing this malicious package.
Malicious code in dc-renewals-layout2 (npm)
Description
The npm package dc-renewals-layout2 version 9999.0.0 contains malicious code in its preinstall script that executes automatically during installation. This script sends a plaintext HTTP GET request to a hardcoded IP address on a non-standard port, transmitting sensitive environment information such as the installer's hostname, username, current working directory, npm registry, and CI repository slug. This behavior is identified as a dependency-confusion reconnaissance beacon, which can reveal private internal package names and enable targeted attacks against the installer's organization.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The dc-renewals-layout2 npm package version 9999.0.0 includes a preinstall script that auto-runs on npm install. This script issues a plaintext HTTP GET request to http://75.119.137.232:31337/depconfuse, sending query parameters containing the installer's hostname, username, current working directory, configured npm registry, and CI repository slug environment variables. The presence of the /depconfuse endpoint and the version fingerprint indicates a dependency-confusion reconnaissance beacon. The CI repository slug can disclose private internal package or repository names, facilitating targeted dependency-confusion attacks. The destination IP and port are unrelated to the package's declared purpose, indicating malicious intent.
Potential Impact
Sensitive environment information from the installer's system and CI environment is exfiltrated to an attacker-controlled server. This leakage can disclose private internal package names and repository details, enabling attackers to craft targeted dependency-confusion attacks against the affected organization. While no direct exploit in the wild is known, the reconnaissance activity poses a significant risk of follow-on supply chain attacks.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing the dc-renewals-layout2 package version 9999.0.0. Review and audit dependencies for unexpected preinstall scripts and network calls. Monitor for suspicious outbound connections during package installation. Check vendor advisories or trusted security sources for updates or patches addressing this malicious package.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12671
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a73573ebf8831d539153632
Added to database: 08/05/2026, 15:31:10 UTC
Last enriched: 08/05/2026, 16:51:48 UTC
Last updated: 08/05/2026, 16:51:48 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.