LWA-2026-11588 confirmed malware
dsh-tauri-ui@0.1.0
Malicious code in dsh-tauri-ui (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
dsh-tauri-ui@0.1.0 is a minimal React UI plugin skeleton for a desktop shell. It ships no lifecycle hooks, no runtime dependencies, and no network or process activity: lib/index.js exports an empty apply() and lib/client.js is a settings-sidebar React component that registers a shell.overlay slot. No executable payload, no exfiltration, and no credential access is present in the code; the package is a benign-looking skeleton with no observable malicious behavior.
- analyzed by
- Leitwacht
- first seen
- Aug 24, 2026, 09:23 AM
- analyzed
- Aug 24, 2026, 09:23 AM
Related advisories
- sm-session@99.0.0
- modules-newline@0.0.6
- @fyxzpediaa/baileys@8.0.15
- kelly-sizing@0.1.0
- @next-fonts/font@1.0.1
- asistenyorstore@8.0.14
- express-session-handler@2.3.3
- chai-as-soul@2.3.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.