LWA-2026-12111 confirmed malware

vl-ui-core@1.0.0

Malicious code in vl-ui-core (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

vl-ui-core@1.0.0 is an empty placeholder package that impersonates the legitimate vl-ui-core UI component library name. The tarball contains only a 55-byte index.js holding a single comment and an empty package.json with no lifecycle hooks, no dependencies, no executable code, and no network activity. It ships no functionality whatsoever while claiming the identity of the real vl-ui-core library, so any project that installs it expecting the genuine component library receives nothing. No runtime payload, C2, or data exfiltration is present in this version.

analyzed by
Leitwacht
first seen
Sep 14, 2026, 12:19 PM
analyzed
Sep 14, 2026, 12:19 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.