webrix-docs1npm
Advisory published Updated
webrix-docs1 is a confirmed malicious npm package (MAL-2026-10081) that typosquats a legitimate package to trick installs (malicious version 10.2.11). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in webrix-docs1 (npm)
What this malware does
The package declares a preinstall hook (node index.js) that fires automatically on npm install. The script requires child_process, os, https, and http, collects hostname, platform, arch, username/uid/gid, shell, home directory, CPU/memory stats, cwd, and the output of whoami/id, then POSTs the JSON payload to a hardcoded Burp Collaborator (oastify.com) subdomain at https://c7kfuaf25guwigaz6r03kxet0k6bu3is.oastify.com/detox56. The package has an empty description and empty author, presents no advertised functionality, and its name mimics the webrix project — consistent with dependency-confusion/typosquat recon. Installing the package directly leaks installer host and user identifiers to an attacker-controlled OAST endpoint.
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
TyposquatFind it
Search your lockfiles and build artifacts for webrix-docs1 (version 10.2.11).
If you installed it — respond
webrix-docs1 is a typosquat — you almost certainly intended a legitimately-named package. Remove webrix-docs1, install the correct package, and rotate any secrets exposed during the install since post-install scripts may have already run.
Did it already run?
If webrix-docs1 was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
Detect & block this
O3 blocks webrix-docs1-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.