LWA-2026-12112 confirmed malware

vl-ui-data-table@1.0.0

Malicious code in vl-ui-data-table (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

vl-ui-data-table@1.0.0 is an empty placeholder package (319 bytes) published under the vl-ui-data-table name, impersonating the vl-ui design-system library namespace. The package contains no executable code: index.js holds only a comment, and package.json declares empty preinstall/postinstall hooks with no dependencies, no bin entries, and no scripts. No network activity, credential access, or payload is present in this version.

analyzed by
Leitwacht
first seen
Sep 14, 2026, 12:19 PM
analyzed
Sep 14, 2026, 12:19 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.