{"id":"MAL-2026-16201","summary":"Malicious code in webpackbootstrap5 (npm)","details":"webpackbootstrap5@5.0.0 typosquats bootstrap and ships a disguised in-browser proxy kit. Its bundled loader (index-z2b7r4.js) XOR-decodes a list of endpoints with a fixed key and injects remote scripts from https://dyingefforlessefforlessours.com via document.head.appendChild, then boots a Scramjet/wisp WebSocket proxy that routes page traffic through operator-controlled relays. The loader matches (same sha256) sibling packages webpackbootstrapscripts and @zaka13/thing by the same publisher (zaka13). Harm is browser-side when the asset is served; no install script runs.","modified":"2026-09-16T01:30:06.422482434Z","published":"2026-09-14T00:00:00Z","database_specific":{"iocs":{"urls":["https://dyingefforlessefforlessours.com/is512uku","wss://wisp.mercurywork.shop/wisp/","wss://theavancehotel.com/fairs/","wss://science-340154168.b-cdn.net/api/"],"domains":["dyingefforlessefforlessours.com","wisp.mercurywork.shop"],"files":[{"paths":["package/index-z2b7r4.js"],"source":"PACKAGE_ARCHIVE","digests":{"sha256":"b2d1d498f4a8f9e967b850ff6ffbc7d53c35b2aeac75fc115cd89a740a596426"},"note":"XOR loader injecting remote scripts from dyingefforlessefforlessours.com and building wisp proxy tunnels"}]}},"affected":[{"package":{"name":"webpackbootstrap5","ecosystem":"npm","purl":"pkg:npm/webpackbootstrap5"},"versions":["5.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/webpackbootstrap5/MAL-2026-16201.json"}}],"schema_version":"1.9.0","credits":[{"name":"pkgwarden","contact":["https://pkgwarden.com"],"type":"FINDER"}]}