LWA-2026-1099 confirmed malware
@veertly/web-app@99.9.9
Malicious code in @veertly/web-app (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Dependency-confusion stub: @veertly/web-app uses a high sentinel version (99.9.9), a scoped name mimicking a real service, and a tiny (1010-byte) tarball. A preinstall hook runs index.js, which collects os.userInfo().username, os.hostname(), and the current working directory, then beacons them to api[.]telegram[.]org/bot8775202566:.../sendMessage with chat_id=1483949647. The error handler is deliberately silent to avoid surfacing failures. Outbound telemetry exfil to an external API at install time.
- analyzed by
- Leitwacht
- first seen
- May 29, 2026, 12:13 AM
- analyzed
- May 29, 2026, 09:42 PM
Related advisories
- @veertly/web-app@100.0.2 same package
- @concerns/i18n@99.9.1
- @coterie-baby/common@99.9.1
- unleash-js@99.9.1
- wm-mapper@99.9.1
- @pisell/pisellos@2.2.164
- @pisell/pisellos@2.2.168
- @pisell/pisellos@2.2.169
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.