LWA-2026-11588 confirmed malware

dsh-tauri-ui@0.1.0

Malicious code in dsh-tauri-ui (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

dsh-tauri-ui@0.1.0 is a minimal React UI plugin skeleton for a desktop shell. It ships no lifecycle hooks, no runtime dependencies, and no network or process activity: lib/index.js exports an empty apply() and lib/client.js is a settings-sidebar React component that registers a shell.overlay slot. No executable payload, no exfiltration, and no credential access is present in the code; the package is a benign-looking skeleton with no observable malicious behavior.

analyzed by
Leitwacht
first seen
Aug 24, 2026, 09:23 AM
analyzed
Aug 24, 2026, 09:23 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.