webpackbootstrap5@5.0.0 typosquats bootstrap and ships a disguised in-browser proxy kit. Its bundled loader (index-z2b7r4.js) XOR-decodes a list of endpoints with a fixed key and injects remote scripts from https://dyingefforlessefforlessours.com via document.head.appendChild, then boots a Scramjet/wisp WebSocket proxy that routes page traffic through operator-controlled relays. The loader matches (same sha256) sibling packages webpackbootstrapscripts and @zaka13/thing by the same publisher (zaka13). Harm is browser-side when the asset is served; no install script runs.
{
"iocs": {
"domains": [
"dyingefforlessefforlessours.com",
"wisp.mercurywork.shop"
],
"files": [
{
"digests": {
"sha256": "b2d1d498f4a8f9e967b850ff6ffbc7d53c35b2aeac75fc115cd89a740a596426"
},
"note": "XOR loader injecting remote scripts from dyingefforlessefforlessours.com and building wisp proxy tunnels",
"paths": [
"package/index-z2b7r4.js"
],
"source": "PACKAGE_ARCHIVE"
}
],
"urls": [
"https://dyingefforlessefforlessours.com/is512uku",
"wss://wisp.mercurywork.shop/wisp/",
"wss://theavancehotel.com/fairs/",
"wss://science-340154168.b-cdn.net/api/"
]
}
}