LWA-2026-12387 confirmed malware
velocity-sdk-ui@1.0.0
Malicious code in velocity-sdk-ui (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
The package ships no executable code — the tarball contains only a package.json manifest that declares a main entry point (index.js) which is not present in the tarball. This is a namespace-claim pattern: the package name is reserved without delivering the referenced code, a common precursor to shipping a malicious payload in a later version. No repository, license, or documentation is included.
- analyzed by
- Leitwacht
- first seen
- Sep 24, 2026, 05:46 PM
- analyzed
- Sep 24, 2026, 05:47 PM
Related advisories
- wallet-connect-adapter@1.4.2
- simple-date-formatter-new-13@1.0.0
- simple-date-formatter-new-11@1.0.0
- solidity-lock@2.21.0
- bunny-stream-react-native@1.0.0
- tostpro@99.99.99
- event-hunter@1.0.0
- amoncasino@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.