LWA-2026-1117 confirmed malware
@visonum/network-quality-sdk@99.9.9
Malicious code in @visonum/network-quality-sdk (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Dependency-confusion stub: @visonum/network-quality-sdk uses a scoped name, sentinel version 99.9.9, and an 825-byte tarball. A preinstall hook runs node index.js, which phones home to a live Telegram bot, exfiltrating os.hostname(), os.userInfo().username, and the current working directory. No NPM_TOKEN/GITHUB_TOKEN/.npmrc theft markers present; the malicious behaviour is the install-time recon beacon to the attacker-controlled Telegram channel.
- analyzed by
- Leitwacht
- first seen
- May 29, 2026, 01:12 AM
- analyzed
- May 29, 2026, 09:48 PM
Related advisories
- @open-banking/cabinet-providers@999.9.5
- @easy-entry/landing-routes@99.9.5
- @easy-entry/outside-registration-fop-navigator@99.9.5
- @easy-entry/routes@99.9.5
- @shell-cabinet/routes@99.9.5
- @shell-landing/routes@99.9.5
- @veertly/web-app@99.9.9
- @concerns/i18n@99.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.