LWA-2026-11842 confirmed malware

@bx-ui-framework/authentication@1.2.0

Malicious code in @bx-ui-framework/authentication (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

The package declares a dependency on itself (@bx-ui-framework/authentication) resolved from a non-registry host, hxxps://repo[.]remoteknight[.]com/bx-ui-framework/authentication. Installing the package causes npm to fetch and execute code from that external attacker-controlled host rather than from the npm registry, allowing the remote host to supply arbitrary code at install time. The bundled index.js is a trivial stub; the actual payload is delivered via the off-registry self-dependency.

analyzed by
Leitwacht
first seen
Sep 2, 2026, 09:11 PM
analyzed
Sep 2, 2026, 09:11 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.