LWA-2026-11890 MAL-2026-15868 ↗ confirmed malware

@bx-ui-framework/microfrontend@15.0.0

Malicious code in @bx-ui-framework/microfrontend (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

The package declares a dependency "microfrontend" pinned to a non-registry URL (hxxps://repo[.]artifactorymanager[.]com/bx-ui-framework/microfrontend) instead of the npm registry. Installing the package causes npm to fetch and install this dependency from that external host, which is not verifiable as legitimate; if the host is compromised, arbitrary code is executed at install time. The package itself is a trivial stub with no other functionality.

analyzed by
Leitwacht
first seen
Aug 27, 2026, 10:01 PM
analyzed
Aug 27, 2026, 10:01 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.