mkt-ui-library@45.0.0
Malicious code in mkt-ui-library (npm)
T1195.002 · Compromise Software Supply ChainT1059.001 · PowerShell
Analysis
mkt-ui-library declares a self-dependency via an attacker-controlled external URL (hxxps://repo[.]securityctrl[.]com/mkt-ui-library) to serve a malicious tarball at install time while keeping the registry publish clean. The package is a ~533-byte stub with a benign index.js that logs a message and a README claiming it is a placeholder to prevent dependency confusion — but a real placeholder would not self-reference via an external-URL dependency. The external URL can serve any payload at install time without leaving traces in the registry tarball.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 06:07 PM
- analyzed
- Jun 10, 2026, 06:08 PM
Related advisories
- dotenv-runtime@1.0.0
- envforge3@1.0.1
- envparse2@1.0.1
- envparse3@1.0.1
- noblox-asset.js@7.4.1
- node-helper@1.5.4
- @stellarshift/chain-metadata@1.0.1
- @stellarshift/evm-address-kit@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.