LWA-2026-1098 confirmed malware
@veertly/web-app@100.0.2
Malicious code in @veertly/web-app (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
A dependency-confusion stub published under the @veertly scope (version 100.0.2, 427 bytes). Its preinstall hook runs node index.js, which sends an HTTP GET beacon to hxxp://13[.]50[.]241[.]66:8080/poc-Swisscom-Abuelkhair during install. The description claims to be an authorized research proof-of-concept, but it performs an unsolicited install-time outbound callback to a bare IP.
- analyzed by
- Leitwacht
- first seen
- May 29, 2026, 12:13 AM
- analyzed
- May 29, 2026, 09:51 PM
Related advisories
- @veertly/web-app@99.9.9 same package
- @veygo/component-library@99.9.2
- @visma-net-platform/module-navigator@99.9.1
- @visonum/network-quality-sdk@99.9.9
- @open-banking/cabinet-providers@999.9.5
- @easy-entry/landing-routes@99.9.5
- @easy-entry/outside-registration-fop-navigator@99.9.5
- @easy-entry/routes@99.9.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.