LWA-2026-1098 confirmed malware

@veertly/web-app@100.0.2

Malicious code in @veertly/web-app (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

A dependency-confusion stub published under the @veertly scope (version 100.0.2, 427 bytes). Its preinstall hook runs node index.js, which sends an HTTP GET beacon to hxxp://13[.]50[.]241[.]66:8080/poc-Swisscom-Abuelkhair during install. The description claims to be an authorized research proof-of-concept, but it performs an unsolicited install-time outbound callback to a bare IP.

analyzed by
Leitwacht
first seen
May 29, 2026, 12:13 AM
analyzed
May 29, 2026, 09:51 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.