bx-ui-view@1.0.0
Malicious code in bx-ui-view (npm)
T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise
Analysis
The package declares a dependency on itself resolved from an external non-registry URL (hxxps://package-access[.]pages[.]dev/bx-ui-view) instead of the npm registry. Installing the package causes npm to fetch and execute code for the bx-ui-view dependency from that attacker-controlled host, which can serve arbitrary code during install. The bundled tarball is a trivial stub; the malicious behaviour is the external-URL dependency that redirects dependency resolution to a non-registry host.
- analyzed by
- Leitwacht
- first seen
- Sep 8, 2026, 07:31 PM
- analyzed
- Sep 8, 2026, 07:32 PM
Related advisories
- @versacode/baileys@1.4.5-beta.1
- @berrysdk/transport@0.1.9
- modules-newline@0.0.6
- @guildai-services/guildai@99.9.1
- bs58-33@6.0.1
- @bottino/baileys@1.0.1
- @morpho-blue-liquidation-bot/data-providers@2.0.0
- @morpho-blue-liquidation-bot/pricers@2.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.