LWA-2026-11673 confirmed malware
@bx-ui-framework/common@15.0.0
Malicious code in @bx-ui-framework/common (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
The package declares a dependency resolved from a non-registry external host: "common": "hxxps://repo[.]artifactorymanager[.]com/bx-ui-framework/common". Installing the package causes npm to fetch and execute this dependency from the external Artifactory server rather than the npm registry, pulling third-party code into the install graph from a host outside the registry.
- analyzed by
- Leitwacht
- first seen
- Aug 27, 2026, 10:44 PM
- analyzed
- Aug 27, 2026, 10:44 PM
Related advisories
- 2fasecretkey@1.1.2
- 2fa-secretkey@1.0.1
- discord-mfa@3.0.0
- vitest-chalk-pro@10.0.7
- hydration-ui-dlx@1.0.0
- eth-pino@2.0.3
- selfsigned-certificate@1.0.0
- tailwindcss-form-styles@0.5.15
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.