LWA-2026-11945 MAL-2026-16064 ↗ confirmed malware

bx-ui-view@1.0.0

Malicious code in bx-ui-view (npm)

T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise

Analysis

The package declares a dependency on itself resolved from an external non-registry URL (hxxps://package-access[.]pages[.]dev/bx-ui-view) instead of the npm registry. Installing the package causes npm to fetch and execute code for the bx-ui-view dependency from that attacker-controlled host, which can serve arbitrary code during install. The bundled tarball is a trivial stub; the malicious behaviour is the external-URL dependency that redirects dependency resolution to a non-registry host.

analyzed by
Leitwacht
first seen
Sep 8, 2026, 07:31 PM
analyzed
Sep 8, 2026, 07:32 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.