Malicious code in @telekom-ods/react-ui-kit (npm)
@telekom-ods/react-ui-kit version 2.6.9 on npm contained malicious code in an install hook that exfiltrated system information (/etc/passwd, /etc/hosts, /etc/shadow, id output) via HTTP POST to an OAST callback server. The compromised package was published under the legitimate telekom-ods publisher account, suggesting either account takeover or supply-chain injection.
- Disclosed
- Last updated
- Blast radius
- All npm users who installed @telekom-ods/react-ui-kit@2.6.9
- Ecosystems
- Attack vectors
- Affected entities
- @telekom-ods/react-ui-kit · 2.6.9
@telekom-ods/react-ui-kit@2.6.9 shipped with a malicious npm install hook that executed a reconnaissance and exfiltration payload. The hook spawned a shell command that read sensitive system files including /etc/passwd, /etc/hosts, and conditionally /etc/shadow if readable, along with output from the id command.
The collected system information was exfiltrated via an HTTP POST request to an out-of-band interaction (OAST) callback server at d9t83osijf9n1gb62e4gxfioysijywqww.oast.me. The victim's whoami and hostname outputs were embedded in the callback URL path (/telekom-ods/$(whoami)/$(hostname)/), allowing the attacker to fingerprint each compromised host and receive system file contents in a single request without needing to log POST bodies.
The malicious version was published under the legitimate telekom-ods publisher account, which had published prior legitimate releases under the same scope. This suggests either a compromised maintainer account or token, or a supply-chain injection into the release pipeline rather than a simple typosquatting attack.
The package has since been removed or remediated from the npm registry.
Indicators of compromise
- Packages
- @telekom-ods/react-ui-kit
- Domains
- d9t83osijf9n1gb62e4gxfioysijywqww.oast.me
Remediation
- Immediately uninstall @telekom-ods/react-ui-kit@2.6.9 from all systems
- Audit npm install logs and package-lock.json files to identify systems that installed the malicious version
- Assume compromise of any system that installed the malicious version; review system logs for unauthorized access or data exfiltration
- Change credentials and review access logs for any accounts that may have been exposed via /etc/passwd or /etc/shadow exfiltration
- Update to a patched version of @telekom-ods/react-ui-kit once available and verified
- Review npm token security and rotate any tokens used by the telekom-ods publisher account
- Monitor for similar malicious packages in the npm registry
Sources
- GitHub Advisory GHSA-7hwp-8qhg-wfmp · GitHub Advisory Database
Cite this entry
"Malicious code in @telekom-ods/react-ui-kit (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 12, 2026; last updated August 12, 2026. https://supplychainattack.org/incident/malicious-code-in-telekom-ods-react-ui-kit-npm-cjb5hn
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2
ChainDrop is a self-propagating npm worm that publishes malicious versions of dozens of npm packages using stolen maintainer credentials. The worm harvests CI/CD credentials and uses an Ethereum-based dead-drop command-and-control mechanism.
ChaindropnpmOtherCompromised packageMalicious maintainerAccount takeover - containedcritical
Malicious code in @antv/gi-assets-algorithm (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-assets-algorithm, in an automated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/gi-sdk-app (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-sdk-app. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/l7-editor (npm)
The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-editor, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.
Mini Shai HuludnpmAccount takeoverCompromised package