LWA-2026-11842 confirmed malware
@bx-ui-framework/authentication@1.2.0
Malicious code in @bx-ui-framework/authentication (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
The package declares a dependency on itself (@bx-ui-framework/authentication) resolved from a non-registry host, hxxps://repo[.]remoteknight[.]com/bx-ui-framework/authentication. Installing the package causes npm to fetch and execute code from that external attacker-controlled host rather than from the npm registry, allowing the remote host to supply arbitrary code at install time. The bundled index.js is a trivial stub; the actual payload is delivered via the off-registry self-dependency.
- analyzed by
- Leitwacht
- first seen
- Sep 2, 2026, 09:11 PM
- analyzed
- Sep 2, 2026, 09:11 PM
Related advisories
- @bx-ui-framework/common@15.0.0
- @stellarshift/abi-tools@1.0.1
- tailwind-container-queries@0.1.1
- @cognition-ai/cli-linux-arm64@3000.6.11
- vitest-cli-pro@10.0.7
- xsjukcnv8low26@1.0.0
- @kentsuki/baileys@1.0.0
- tailwindcss-forms-style@0.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.