LWA-2026-3980 confirmed malware

mkt-ui-library@45.0.0

Malicious code in mkt-ui-library (npm)

T1195.002 · Compromise Software Supply ChainT1059.001 · PowerShell

Analysis

mkt-ui-library declares a self-dependency via an attacker-controlled external URL (hxxps://repo[.]securityctrl[.]com/mkt-ui-library) to serve a malicious tarball at install time while keeping the registry publish clean. The package is a ~533-byte stub with a benign index.js that logs a message and a README claiming it is a placeholder to prevent dependency confusion — but a real placeholder would not self-reference via an external-URL dependency. The external URL can serve any payload at install time without leaving traces in the registry tarball.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 06:07 PM
analyzed
Jun 10, 2026, 06:08 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.