LWA-2026-11864 confirmed malware
windows-dev-bootstrap-vscode-part-1@0.2.0
Malicious code in windows-dev-bootstrap-vscode-part-1 (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
The package contains no source code — only a ~120MB Windows PE executable (payload/vscode.part-0, an MZ/PE binary with .text/.data/.rsrc sections) shipped as "part 1 of 2" of a binary payload. A companion package (windows-dev-bootstrap) is intended to extract and execute this binary. The package is a distribution vehicle for a large Windows executable delivered through the npm registry, with no install-time code of its own.
- analyzed by
- Leitwacht
- first seen
- Sep 3, 2026, 05:25 PM
- analyzed
- Sep 3, 2026, 05:26 PM
Related advisories
- fieldbase-webapplication-buildtools@99.99.99
- mcp-consultasdeveiculos@0.0.1
- @bx-ui-framework/authentication@1.2.0
- @stellarshift/abi-tools@1.0.1
- tailwind-container-queries@0.1.1
- @cognition-ai/cli-linux-arm64@3000.6.11
- vitest-cli-pro@10.0.7
- xsjukcnv8low26@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.