Malicious code in dpdgroup-css (npm)
The npm package dpdgroup-css version 2.0.1 contains malicious code that executes during installation. It runs a setup script that collects the installer's machine hostname and sends it to an external hardcoded IP address via an HTTP request. This behavior resembles a dependency confusion attack, where a public package mimics an internal package to exfiltrate internal build-host information. The package provides no legitimate functionality.
AI Analysis
Technical Summary
The dpdgroup-css npm package version 2.0.1 declares preinstall and postinstall lifecycle hooks that execute a setup.js script on every npm install. This script reads the local machine's hostname using os.hostname() and sends it via an HTTP GET request to a hardcoded external IP address (http://89.116.25.133:4444/dpdgroup-css/<hostname>) with the hostname also included in an X-PoC-Host header. The package name suggests it is impersonating an internal DPDgroup package, consistent with a dependency confusion attack. No legitimate library functionality is present, indicating the package is malicious and designed to leak internal host identifiers to an external attacker-controlled endpoint.
Potential Impact
The malicious package leaks the hostname of the machine installing it to an external attacker-controlled server. This disclosure of internal build-host identifiers can aid attackers in reconnaissance and further targeted attacks. The package does not provide any legitimate functionality and runs code automatically during installation, which can lead to unintended data exposure.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing dpdgroup-css version 2.0.1 from public npm registries. Verify internal package scopes and ensure dependency resolution does not pull public packages that impersonate internal ones. Monitor and audit package dependencies to prevent dependency confusion attacks. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Malicious code in dpdgroup-css (npm)
Description
The npm package dpdgroup-css version 2.0.1 contains malicious code that executes during installation. It runs a setup script that collects the installer's machine hostname and sends it to an external hardcoded IP address via an HTTP request. This behavior resembles a dependency confusion attack, where a public package mimics an internal package to exfiltrate internal build-host information. The package provides no legitimate functionality.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The dpdgroup-css npm package version 2.0.1 declares preinstall and postinstall lifecycle hooks that execute a setup.js script on every npm install. This script reads the local machine's hostname using os.hostname() and sends it via an HTTP GET request to a hardcoded external IP address (http://89.116.25.133:4444/dpdgroup-css/<hostname>) with the hostname also included in an X-PoC-Host header. The package name suggests it is impersonating an internal DPDgroup package, consistent with a dependency confusion attack. No legitimate library functionality is present, indicating the package is malicious and designed to leak internal host identifiers to an external attacker-controlled endpoint.
Potential Impact
The malicious package leaks the hostname of the machine installing it to an external attacker-controlled server. This disclosure of internal build-host identifiers can aid attackers in reconnaissance and further targeted attacks. The package does not provide any legitimate functionality and runs code automatically during installation, which can lead to unintended data exposure.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing dpdgroup-css version 2.0.1 from public npm registries. Verify internal package scopes and ensure dependency resolution does not pull public packages that impersonate internal ones. Monitor and audit package dependencies to prevent dependency confusion attacks. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13444
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a75744cbf8831d539d9b013
Added to database: 08/07/2026, 05:59:40 UTC
Last enriched: 08/07/2026, 06:12:37 UTC
Last updated: 08/07/2026, 07:08:49 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.