@bx-ui-framework/microfrontend@15.0.0
Malicious code in @bx-ui-framework/microfrontend (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
The package declares a dependency "microfrontend" pinned to a non-registry URL (hxxps://repo[.]artifactorymanager[.]com/bx-ui-framework/microfrontend) instead of the npm registry. Installing the package causes npm to fetch and install this dependency from that external host, which is not verifiable as legitimate; if the host is compromised, arbitrary code is executed at install time. The package itself is a trivial stub with no other functionality.
- analyzed by
- Leitwacht
- first seen
- Aug 27, 2026, 10:01 PM
- analyzed
- Aug 27, 2026, 10:01 PM
Related advisories
- @bx-ui-framework/authentication@1.2.0
- @bx-ui-framework/common@15.0.0
- 2fasecretkey@1.1.2
- 2fa-secretkey@1.0.1
- discord-mfa@3.0.0
- vitest-chalk-pro@10.0.7
- hydration-ui-dlx@1.0.0
- eth-pino@2.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.