LWA-2026-12387 confirmed malware

velocity-sdk-ui@1.0.0

Malicious code in velocity-sdk-ui (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

The package ships no executable code — the tarball contains only a package.json manifest that declares a main entry point (index.js) which is not present in the tarball. This is a namespace-claim pattern: the package name is reserved without delivering the referenced code, a common precursor to shipping a malicious payload in a later version. No repository, license, or documentation is included.

analyzed by
Leitwacht
first seen
Sep 24, 2026, 05:46 PM
analyzed
Sep 24, 2026, 05:47 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.